CVE-2026-74006: WordPress WP Table Builder plugin <= 2.2.0 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
Affected Software
1 affected component
WP Table Builder<=2.2.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can realistically exploit this issue?
Sites using WP Table Builder version 2.2.0 or earlier are affected when a user has Contributor-level access. The issue does not require user interaction and can be exploited remotely by an authenticated low-privileged user.
2
What can be done if patching is not immediately possible?
The provided data identifies affected versions through 2.2.0 but does not specify a fixed release or workaround. Until a fix is available, restrict Contributor accounts to trusted users and review whether Contributor access is necessary.