CVE-2026-2306Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary Ninja Tables in the database which can lead to database pollution and resource exhaustion.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-06: 3Technical Details · 2026-05-06: 305-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2306 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `create… https://www.cve.org/CVERecord?id=CVE-2026-2306

    Post summary

    An announcement of CVE-2026-2306 reveals that the Ninja Tables WordPress plugin is vulnerable to unauthorized database table creation caused by missing authorization checks.

    00010239
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2306 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `create… https://www.cve.org/CVERecord?id=CVE-2026-2306 ----- Traducción: CVE-2026-2306 El … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-2306, highlighting that the Ninja Tables WordPress plugin can create database tables without authorization due to missing checks. No PoC, exploit code, patch, or evidence of active use is provided.

    0000048
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2306 Unauthorized Database Table Creation in Ninja Tables WordPress Plugin 5.2.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2306

    Post summary

    A new vulnerability (CVE-2026-2306) that allows unauthorized database table creation in Ninja Tables WordPress Plugin 5.2.6 has been disclosed, but no exploit, patch, or evidence of active exploitation is provided.

    0000045
    4.0K followersView on X

Explore more