CVE-2026-4119 CRITICAL

CVE-2026-4119: Create DB Tables <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php

Vendor Jppreus
Product Create DB Tables
Weakness CWE-862 · Missing authorization
Published April 22, 2026
Last update April 22, 2026

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability checks via current_user_can() or nonce verification via wp_verify_nonce()/check_admin_referer(). The admin_post hook only requires the user to be logged in, meaning any authenticated user including Subscribers can access these endpoints. The cdbt_delete_db_table() function takes a user-supplied table name from $_POST['db_table'] and executes a DROP TABLE SQL query, allowing any authenticated attacker to delete any database table including critical WordPress core tables such as wp_users or wp_options. The cdbt_create_new_table() function similarly allows creating arbitrary tables. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary database tables and delete any existing database table, potentially destroying the entire WordPress installation.

Explanation of Vulnerability in Simple Terms

02Summary

Create DB Tables versions 1.2.1 and earlier lack authorization checks on database operations. An unauthenticated attacker can modify or delete database tables without permission. No authentication or user interaction is required. Sites running affected versions should update immediately.

What an attacker can do

03Attacker Capabilities

Modify or delete database tables without authentication.

Potential impact on your site

04Site Impact

Database tables can be altered or destroyed by anyone on the internet, causing data loss or site malfunction.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication required.

Key dates

06Disclosure timeline

April 22, 2026 CVE published
April 22, 2026 Record updated

Related vulnerabilities

08Related CVE