Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4119

32
FAUCET Score

VULNERABILITY OVERVIEW CVE-2026-4119 affects the Create DB Tables WordPress plugin in versions up to and including 1.2.1. The vulnerability stems from inadequate authorization controls on administrative functions that manage database tables. The vulnerable admin_post action hooks for creating and deleting tables lack proper capability checks and nonce verification, allowing any authenticated user to invoke these functions regardless of their privilege level. SEVERITY ASSESSMENT This is a critical vulnerability with a CVSS score of 9.1. The attack requires only network access with low complexity and no user interaction. Notably, the vulnerability does not require elevated privileges, as any logged-in user including those with Subscriber-level access can exploit it. The impact is severe: authenticated attackers can execute arbitrary SQL DROP TABLE commands to delete critical WordPress tables such as wp_users and wp_options, or create malicious database tables. This could result in complete destruction of a WordPress installation and unauthorized data manipulation. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list. The EPSS score of 0.00021 indicates minimal real-world exploitation activity currently. However, the straightforward nature of the authorization bypass and the destructive potential warrant immediate patching. Organizations running affected versions should update the plugin to version 1.2.2 or later without delay to prevent potential abuse.

Impacted Technologies

VendorProductVersion(s)CPE
JppreusCreate DB Tables
>= 0, <= 1.2.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.73%
Probability of exploitation in next 30 days
EPSS Percentile
50.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0073 is in the 33rd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/create-db-tables/tags/1.2.1/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/tags/1.2.1/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/tags/1.2.1/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/tags/1.2.1/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/tags/1.2.1/create-new-table.php
plugins.trac.wordpress.org / browser/create-db-tables/tags/1.2.1/create-new-table.php
plugins.trac.wordpress.org / browser/create-db-tables/trunk/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/trunk/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/trunk/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/trunk/create-db-tables.php
plugins.trac.wordpress.org / browser/create-db-tables/trunk/create-new-table.php
plugins.trac.wordpress.org / browser/create-db-tables/trunk/create-new-table.php
wordfence.com / threat-intel/vulnerabilities/id/d1a3bc4b-cc17-4728-b242-13841b5f7660