CVE · High

CVE-2024-45293 — TablePress – Tables in WordPress made easy [tablepress] < 2.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-45293 TablePress – Tables in WordPress made easy [tablepress] < 2.4.3 Improper Restriction of XML External Entity Reference High 7.5 < 2.4.3 2.4.3 2024-10-07

CVE-2024-45293

TablePress versions before 2.4.3 contain an XML external entity (XXE) vulnerability through its use of PHPSpreadsheet library, which can be exploited by uploading a specially crafted XLSX file with modified XML structure and whitespace manipulation to bypass the security scanner. An attacker could exploit this flaw to disclose sensitive server files and information from sites that permit users to upload Excel spreadsheets. The vulnerability stems from a flawed encoding detection function that fails to properly identify XML encoding when whitespace is inserted around the equals sign in encoding attributes, allowing UTF-7 encoded XXE payloads to pass through security checks. Users should upgrade to version 2.4.3 or later to address this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.