CVE · Medium

CVE-2025-12324 — TablePress – Tables in WordPress made easy [tablepress] < 3.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12324 TablePress – Tables in WordPress made easy [tablepress] < 3.2.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.2.5 3.2.5 2025-11-03

CVE-2025-12324

The TablePress plugin for WordPress contains a security flaw that allows malicious users with contributor privileges or higher to insert unauthorized code into webpage attributes through the `table` shortcode. This vulnerability affects all versions of the plugin up to and including 3.2.3, due to inadequate filtering of user-submitted data. As a result, attackers can embed executable scripts in pages that will be executed when accessed by other users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.