CVE-2024-45293
TablePress versions before 2.4.3 contain an XML external entity (XXE) vulnerability through its use of PHPSpreadsheet library, which can be exploited by uploading a specially crafted XLSX file with modified XML structure and whitespace manipulation to bypass the security scanner. An attacker could exploit this flaw to disclose sensitive server files and information from sites that permit users to upload Excel spreadsheets. The vulnerability stems from a flawed encoding detection function that fails to properly identify XML encoding when whitespace is inserted around the equals sign in encoding attributes, allowing UTF-7 encoded XXE payloads to pass through security checks. Users should upgrade to version 2.4.3 or later to address this issue.
Based on public CVE data (MITRE/NVD).