CVE · Medium

CVE-2019-20180 — TablePress – Tables in WordPress made easy [tablepress] < 2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-20180 TablePress – Tables in WordPress made easy [tablepress] < 2.0 Improper Neutralization of Formula Elements in a CSV File Medium 6.8 < 2.0 2.0 2020-01-09

CVE-2019-20180

The TablePress plugin for WordPress through version 1.14 contains a CSV injection vulnerability in the tablepress[data] parameter that allows authenticated users with author-level permissions or higher to inject malicious code into exported CSV files, potentially enabling code execution when those files are opened in a vulnerable environment on a local system. Although the CVE initially indicated the issue was resolved in version 1.10, testing confirmed the vulnerability remained present through version 1.14. The flaw was ultimately remedied in version 2.0. The practical risk of exploitation is considered low due to the technical complexity involved and existing protective mechanisms in modern systems.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.