LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4119 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: April 22, 2026

Create DB Tables WordPress Plugin - Authorization Bypass

Published: April 22, 2026Updated: April 22, 2026Remote Exploitable

Overview

Create DB Tables WordPress plugin <= 1.2.1 contains an authorization bypass caused by missing capability and nonce checks in admin_post hooks, letting authenticated users with Subscriber-level access create or delete arbitrary database tables.

Severity & Score

Severity: Critical
CVSS Score: 9.1

Impact

Authenticated attackers can create or delete any database table, potentially destroying the entire WordPress installation.

Mitigation

Update to the latest version with proper capability and nonce checks.

Details

CVE ID
CVE-2026-4119
Severity
Critical
CVSS Score
9.1
Type
broken_access_control
Status
rejected

CWE

  • CWE-862

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H