CVE-2026-4119
Last modified
CVE-2026-4119 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability checks via current_user_can() or nonce verification via wp_verify_nonce()/check_admin_referer(). EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability checks via current_user_can() or nonce verification via wp_verify_nonce()/check_admin_referer(). The admin_post hook only requires the user to be logged in, meaning any authenticated user including Subscribers can access these endpoints. The cdbt_delete_db_table() function takes a user-supplied table name from $_POST['db_table'] and executes a DROP TABLE SQL query, allowing any authenticated attacker to delete any database table including critical WordPress core tables such as wp_users or wp_options. The cdbt_create_new_table() function similarly allows creating arbitrary tables. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary database tables and delete any existing database table, potentially destroying the entire WordPress installation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4119?
How severe is CVE-2026-4119?
How do I fix CVE-2026-4119?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-41183FreeScout is a free self-hosted help desk and shared mailbox…4.3
- CVE-2026-41184In Calico, the install-cni init container logs the rendered …6.5
- CVE-2026-41185When Calico is configured with the Azure IPAM plugin, the Ca…6.5
- CVE-2026-41186When Calico's shared debug server is enabled (disabled by de…7.5
- CVE-2026-41187Calico's apiserver wraps tier-scoped resources so that every…6.5
- CVE-2026-41189FreeScout is a free self-hosted help desk and shared mailbox…7.1
- CVE-2026-41190FreeScout is a free self-hosted help desk and shared mailbox…7.1
- CVE-2026-41191FreeScout is a free self-hosted help desk and shared mailbox…7.1
- CVE-2026-41192FreeScout is a free self-hosted help desk and shared mailbox…7.1
- CVE-2026-41193FreeScout is a free self-hosted help desk and shared mailbox…9.1
- CVE-2026-41194FreeScout is a free self-hosted help desk and shared mailbox…5.4
- CVE-2026-41195mosparo is the modern solution to protect your online forms …5
Are you affected by CVE-2026-4119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
