CVE-2024-13362
TablePress – Tables in WordPress made easy
Minimum safe version
3.2.5
Update to 3.2.5 or later to address 12 fixable vulnerabilities
CVE-2025-12324
TablePress <= 3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_debug Parameter
TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters
TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting
CVE-2024-45293
WordPress TablePress Plugin <= 2.4.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-4354
TablePress <= 2.2.4 - Authenticated(Author+) Server Side Request Forgery(SSRF) via _get_import_files
WordPress TablePress Plugin < 2.1.5 is vulnerable to Cross Site Scripting (XSS)
WordPress TablePress plugin <=1.8 - Authenticated XML External Entity (XXE) vulnerability
TablePress <= 1.14 - Authenticated (Author+) CSV Injection