CVE · Medium

CVE-2017-10889 — TablePress – Tables in WordPress made easy [tablepress] < 1.8.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-10889 TablePress – Tables in WordPress made easy [tablepress] < 1.8.1 Improper Restriction of XML External Entity Reference Medium 4.3 < 1.8.1 1.8.1 2017-07-04

CVE-2017-10889

TablePress, a WordPress plugin for creating and managing tables, contains an XML external entity (XXE) injection vulnerability due to improper restriction of external entity references. This flaw allows attackers to exploit XML parsing to access sensitive data or perform other malicious actions. The vulnerability affects versions prior to 1.8.1 and was reported by Yuji Tounai of NTT Communications Corporation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.