CVE-2026-4119Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability checks via current_user_can() or nonce verification via wp_verify_nonce()/check_admin_referer(). The admin_post hook only requires the user to be logged in, meaning any authenticated user including Subscribers can access these endpoints. The cdbt_delete_db_table() function takes a user-supplied table name from $_POST['db_table'] and executes a DROP TABLE SQL query, allowing any authenticated attacker to delete any database table including critical WordPress core tables such as wp_users or wp_options. The cdbt_create_new_table() function similarly allows creating arbitrary tables. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary database tables and delete any existing database table, potentially destroying the entire WordPress installation.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-22); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-05-06: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-24: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 1Technical Details · 2026-05-06: 104-2204-2304-2405-06
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-222
Disclosure1Patch1
2026-04-231
Disclosure1
2026-04-241
PoC1
2026-05-061
Patch1
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4119 — CVSS 9.1/10 █████████░ The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/9HUaon8xZW

    Post summary

    The post announces that CVE-2026-4119 allows an authorization bypass in the Create DB Tables WordPress plugin and urges users to apply the patch immediately.

    1001054
    28 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    WooCommerce admins: check your plugins for Create DB Tables <= 1.2.1. CVE-2026-4119 is a critical WordPress authorization bypass that may let even low-privilege authenticated users create or delete database tables. What’s the risk: deleted wp_users, broken checkout, lost orders, downtime, and full store disruption. How to protect your site: remove or update the plugin, audit subscriber accounts, review DB changes, restore from clean backups if needed, and scan for persistence. https://quttera.com/wordpress-malware-scanner #WooCommerce #WordPressSecurity #CVE20264119 #PluginSecurity #EcommerceSecurity #Quttera #Malware #CVE #SilentRisk

    Post summary

    The post announces the critical WordPress authorization bypass CVE-2026-4119 affecting WooCommerce plug‑ins, explains its impact, and recommends removing/updating the plugin along with other mitigations.

    0000067
    40 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4119-create-db-tables-version-1-2-1-critical-vulnerability-proof-of-concept CVE-2026-4119 #WordPress plugin #vulnerability create-db-tables #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for CVE‑2026‑4119 in a WordPress plugin is referenced, but no exploit, patch, or active usage claims are provided.

    0000060
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4119 The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks … https://www.cve.org/CVERecord?id=CVE-2026-4119

    Post summary

    The Create DB Tables WordPress plugin is vulnerable to an authorization bypass flaw affecting all versions up to 1.2.1, with details listed at the CVE record link.

    0000097
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4119: Create DB Tables &lt;= 1.2.1 - Missi... Subscriber-level users can DROP TABLE any database including wp_users via unprotected admin_post hooks - instant site de... https://zerodaysignal.com/vulnerability/CVE-2026-4119 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-4119, a vulnerability that allows subscriber-level users to drop tables via unprotected admin_post hooks, with a link to a site that likely holds further details.

    0000081
    218 followersView on X

Explore more