CVE · Medium

CVE-2024-23825 — TablePress – Tables in WordPress made easy [tablepress] < 2.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-23825 TablePress – Tables in WordPress made easy [tablepress] < 2.2.5 Server-Side Request Forgery (SSRF) Medium 4.9 < 2.2.5 2.2.5 2024-01-30

CVE-2024-23825

TablePress versions before 2.2.5 contain a server-side request forgery vulnerability in its table import functionality. When users provide URLs for importing tables, the plugin does not adequately validate the input, allowing attackers to direct requests to unintended network destinations and retrieve their responses. In cloud environments such as AWS, this flaw could enable attackers to make unauthorized requests to instance metadata APIs, potentially exposing sensitive internal data and credentials if the instance is misconfigured.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.