TablePress is a WordPress plugin that provides table creation and management functionality embedded across countless WordPress sites. Its vulnerability surface centers on input-handling and data-processing weaknesses typical of web-facing content plugins, with recurring issues in cross-site scripting, server-side request forgery, formula injection in CSV exports, and XML external entity handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tablepress over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56051HIGH Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2019-20180MEDIUM The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with | Jan 9, 2020 | 6.8 | 23 | NO | NO |
CVE-2024-4354MEDIUM The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_impo | Jun 7, 2024 | 6.4 | 19 | NO | NO |
CVE-2025-5096MEDIUM The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data-s-content-padding', 'data-s-title', and 'data-footer' data- | May 23, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-23825MEDIUM TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered i | Jan 30, 2024 | 4.9 | 17 | NO | NO |
CVE-2025-2685MEDIUM The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up to, and including | Mar 27, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-9595MEDIUM The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2. | Oct 12, 2024 | 5.4 | 16 | NO | NO |
CVE-2017-10889MEDIUM TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors. | Nov 17, 2017 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tablepress.
Media articles that mention a CVE ID that affects a product developed by Tablepress — matched by CVE ID, not by vendor name.