Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.124729
Category:Web application abuses
Title:WordPress TablePress Plugin < 2.4.3 Multiple Vulnerabilities
Summary:The WordPress plugin 'TablePress' is prone to multiple; vulnerabilities.
Description:Summary:
The WordPress plugin 'TablePress' is prone to multiple
vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- CVE-2024-9595: The TablePress is vulnerable to Stored Cross-Site Scripting via the
table cell content due to insufficient input sanitization and output escaping.

- CVE-2024-45293: The security scanner that prevents XXE attacks in the XLSX reader can
be bypassed by slightly modifying the XML structure, utilizing white spaces. On servers
that allow users to upload their own Excel (XLSX) sheets, Server files, and sensitive
information can be disclosed by providing a crafted sheet.

Affected Software/OS:
WordPress TablePress plugin prior to version 2.4.3.

Solution:
Update to version 2.4.3 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2024-9595
Common Vulnerability Exposure (CVE) ID: CVE-2024-45293
CopyrightCopyright (C) 2025 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.