{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-table-builder--drag--drop-table-builder--2.2.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:wp_table_builder_drag_drop_table_builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-6922"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Table Builder – Drag \u0026 Drop Table Builder (\u003c= 2.2.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin-vulnerability","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Table Builder - Drag \u0026amp; Drop Table Builder plugin for WordPress is affected by an incorrect authorization vulnerability (CVE-2026-6922) present in all versions up to and including 2.2.1. The flaw resides within the \u003ccode\u003etrash_table_bulk()\u003c/code\u003e and \u003ccode\u003erestore_table_bulk()\u003c/code\u003e functions. Due to an operator precedence error in the post-type validation guard, the security check fails to execute as intended. Furthermore, the permission callback associated with these functions only verifies that the user possesses a plugin-specific role, failing to perform necessary per-post-type or ownership checks. Consequently, any authenticated user - including those with low-privileged subscriber access - can provide arbitrary post IDs to trash or restore any content on the WordPress installation, including posts, pages, and custom post types. This vulnerability poses a significant risk to site integrity and availability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users with minimal privileges to perform unauthorized administrative actions against site content. Attackers can mass-trash or restore posts and pages, potentially causing widespread service disruption, content loss, or unauthorized content visibility changes. This vulnerability affects any WordPress site utilizing the vulnerable version of the WP Table Builder plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the WP Table Builder - Drag \u0026amp; Drop Table Builder plugin to a version released after 2.2.1 immediately to resolve CVE-2026-6922.\u003c/li\u003e\n\u003cli\u003eReview audit logs for \u003ccode\u003etrash_table_bulk\u003c/code\u003e or \u003ccode\u003erestore_table_bulk\u003c/code\u003e function calls initiated by accounts with subscriber-level permissions.\u003c/li\u003e\n\u003cli\u003eRestrict administrative plugin access and sensitive action capabilities to high-privileged roles until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T08:34:32Z","date_published":"2026-09-22T08:34:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-table-builder-auth-bypass/","summary":"An incorrect authorization vulnerability in WP Table Builder versions \u003c= 2.2.1 allows authenticated subscribers to trash or restore arbitrary posts via faulty permission checks.","title":"Authorization Bypass in WP Table Builder Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-table-builder-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Table Builder – Drag \u0026 Drop Table Builder (\u003c= 2.2.1)","version":"https://jsonfeed.org/version/1.1"}