<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WP Table Builder – Drag &amp; Drop Table Builder (&lt;= 2.2.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wp-table-builder--drag--drop-table-builder--2.2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 08:34:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wp-table-builder--drag--drop-table-builder--2.2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in WP Table Builder Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-wp-table-builder-auth-bypass/</link><pubDate>Tue, 22 Sep 2026 08:34:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wp-table-builder-auth-bypass/</guid><description>An incorrect authorization vulnerability in WP Table Builder versions &lt;= 2.2.1 allows authenticated subscribers to trash or restore arbitrary posts via faulty permission checks.</description><content:encoded><![CDATA[<p>The WP Table Builder - Drag &amp; Drop Table Builder plugin for WordPress is affected by an incorrect authorization vulnerability (CVE-2026-6922) present in all versions up to and including 2.2.1. The flaw resides within the <code>trash_table_bulk()</code> and <code>restore_table_bulk()</code> functions. Due to an operator precedence error in the post-type validation guard, the security check fails to execute as intended. Furthermore, the permission callback associated with these functions only verifies that the user possesses a plugin-specific role, failing to perform necessary per-post-type or ownership checks. Consequently, any authenticated user - including those with low-privileged subscriber access - can provide arbitrary post IDs to trash or restore any content on the WordPress installation, including posts, pages, and custom post types. This vulnerability poses a significant risk to site integrity and availability.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated users with minimal privileges to perform unauthorized administrative actions against site content. Attackers can mass-trash or restore posts and pages, potentially causing widespread service disruption, content loss, or unauthorized content visibility changes. This vulnerability affects any WordPress site utilizing the vulnerable version of the WP Table Builder plugin.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the WP Table Builder - Drag &amp; Drop Table Builder plugin to a version released after 2.2.1 immediately to resolve CVE-2026-6922.</li>
<li>Review audit logs for <code>trash_table_bulk</code> or <code>restore_table_bulk</code> function calls initiated by accounts with subscriber-level permissions.</li>
<li>Restrict administrative plugin access and sensitive action capabilities to high-privileged roles until the patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>plugin-vulnerability</category><category>authorization-bypass</category></item></channel></rss>