VULNERABILITY OVERVIEW CVE-2026-4119 affects the Create DB Tables WordPress plugin in versions up to and including 1.2.1. The vulnerability stems from inadequate authorization controls on administrative functions that manage database tables. The vulnerable admin_post action hooks for creating and deleting tables lack proper capability checks and nonce verification, allowing any authenticated user to invoke these functions regardless of their privilege level. SEVERITY ASSESSMENT This is a critical vulnerability with a CVSS score of 9.1. The attack requires only network access with low complexity and no user interaction. Notably, the vulnerability does not require elevated privileges, as any logged-in user including those with Subscriber-level access can exploit it. The impact is severe: authenticated attackers can execute arbitrary SQL DROP TABLE commands to delete critical WordPress tables such as wp_users and wp_options, or create malicious database tables. This could result in complete destruction of a WordPress installation and unauthorized data manipulation. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list. The EPSS score of 0.00021 indicates minimal real-world exploitation activity currently. However, the straightforward nature of the authorization bypass and the destructive potential warrant immediate patching. Organizations running affected versions should update the plugin to version 1.2.2 or later without delay to prevent potential abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Jppreus | Create DB Tables | >= 0, <= 1.2.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.