


Perceptive Security
SOC/SIEM Consultancy

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post actio…
Published:
21 April 2026 at 22:00:00
Alert date:
22 April 2026 at 22:11:22
Source:
nvd.nist.gov
Web Technologies, Database & Storage
The Create DB Tables plugin for WordPress versions up to 1.2.1 contains a critical authorization bypass vulnerability. The plugin fails to implement proper capability checks or nonce verification for admin_post action hooks, allowing any authenticated user including Subscribers to access table creation and deletion endpoints. Attackers can exploit the cdbt_delete_db_table() function to execute DROP TABLE SQL queries against any database table, including critical WordPress core tables like wp_users or wp_options. The vulnerability also allows creation of arbitrary database tables through the cdbt_create_new_table() function, potentially enabling complete destruction of WordPress installations.
Technical details
Mitigation steps:
Affected products:
WordPress Create DB Tables Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4119
https://plugins.trac.wordpress.org/browser/create-db-tables/tags/1.2.1/create-db-tables.php#L370
https://plugins.trac.wordpress.org/browser/create-db-tables/tags/1.2.1/create-db-tables.php#L376
https://plugins.trac.wordpress.org/browser/create-db-tables/tags/1.2.1/create-db-tables.php#L405
https://plugins.trac.wordpress.org/browser/create-db-tables/tags/1.2.1/create-db-tables.php#L408
https://plugins.trac.wordpress.org/browser/create-db-tables/tags/1.2.1/create-new-table.php#L14
https://plugins.trac.wordpress.org/browser/create-db-tables/tags/1.2.1/create-new-table.php#L69
https://plugins.trac.wordpress.org/browser/create-db-tables/trunk/create-db-tables.php#L370
https://plugins.trac.wordpress.org/browser/create-db-tables/trunk/create-db-tables.php#L376
https://plugins.trac.wordpress.org/browser/create-db-tables/trunk/create-db-tables.php#L405
https://plugins.trac.wordpress.org/browser/create-db-tables/trunk/create-db-tables.php#L408
https://plugins.trac.wordpress.org/browser/create-db-tables/trunk/create-new-table.php#L14
https://plugins.trac.wordpress.org/browser/create-db-tables/trunk/create-new-table.php#L69
https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a3bc4b-cc17-4728-b242-13841b5f7660?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
