WP Table Builder – Drag & Drop Table Builder Security & Risk Analysis

wordpress.org/plugins/wp-table-builder

Drag and Drop Table Builder Plugin. Build Responsive Tables Easily.

50K active installs v2.1.10 PHP 7.4+ WP 4.9+ Updated Mar 6, 2026
drag-and-droptabletable-builder
95
A · Safe
CVEs total10
Unpatched0
Last CVEJan 8, 2026
Safety Verdict

Is WP Table Builder – Drag & Drop Table Builder Safe to Use in 2026?

Generally Safe

Score 95/100

WP Table Builder – Drag & Drop Table Builder has a strong security track record. Known vulnerabilities have been patched promptly.

10 known CVEsLast CVE: Jan 8, 2026Updated 28d ago
Risk Assessment

The plugin "wp-table-builder" v2.1.10 exhibits a mixed security posture. On the positive side, the static analysis shows a strong adherence to secure coding practices regarding SQL queries, with all queries using prepared statements. The output escaping is also very good, with 94% of outputs properly escaped. Furthermore, the attack surface from AJAX handlers and REST API routes is zero, and there are no detected critical or high-severity taint flows. The absence of unpatched CVEs in its history is also a significant strength.

However, several areas raise concerns. The presence of 10 known medium-severity vulnerabilities in its history, including Incorrect Authorization, Cross-site Scripting, and CSRF, indicates a pattern of past security weaknesses that, while currently patched, suggest a higher potential for future disclosures. The complete absence of nonce checks across the entire plugin is a major oversight, especially considering the presence of a shortcode which can be a potential entry point for attacks. While there are capability checks, the lack of nonce validation leaves room for potential cross-site request forgery scenarios. The bundling of Freemius v1.0, if outdated, could also introduce risks.

In conclusion, while "wp-table-builder" has made strides in secure coding for SQL and output handling, the historical prevalence of medium-severity vulnerabilities and the critical omission of nonce checks present notable risks. The plugin's security relies heavily on timely patching of past vulnerabilities, and the lack of nonce protection warrants immediate attention.

Key Concerns

  • 10 medium vulnerabilities in history
  • No nonce checks
  • Bundled library (Freemius v1.0)
Vulnerabilities
10

WP Table Builder – Drag & Drop Table Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2023
2023
3 CVEs in 2024
2024
4 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
10

10 total CVEs

CVE-2025-13753medium · 4.3Incorrect Authorization

WP Table Builder <= 2.0.19 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table Creation

Jan 8, 2026 Patched in 2.0.20 (64d)
CVE-2025-8604medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Table Builder – WordPress Table Plugin <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Aug 14, 2025 Patched in 2.0.13 (1d)
CVE-2025-55711medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Table Builder <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 14, 2025 Patched in 2.0.13 (6d)
CVE-2025-49286medium · 4.3Cross-Site Request Forgery (CSRF)

WP Table Builder <= 2.0.6 - Cross-Site Request Forgery

Jun 5, 2025 Patched in 2.0.7 (7d)
CVE-2025-32598medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Table Builder <= 2.0.5 - Reflected Cross-Site Scripting

Apr 9, 2025 Patched in 2.0.6 (15d)
CVE-2024-43125medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Table Builder – WordPress Table Plugin <= 1.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 7, 2024 Patched in 1.5.0 (8d)
CVE-2024-3282medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Table Builder <= 1.5.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Aug 2, 2024 Patched in 1.5.1 (27d)
CVE-2024-4700medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Table Builder – WordPress Table Plugin <= 1.4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 20, 2024 Patched in 1.4.15 (1d)
CVE-2022-46852medium · 4.4Cross-Site Request Forgery (CSRF)

WP Table Builder – WordPress Table Plugin <= 1.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting

Feb 20, 2023 Patched in 1.4.7 (337d)
WF-cb4681a5-d722-4585-97d3-370938c079a2-wp-table-buildermedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Table Builder – WordPress Table Plugin <= 1.3.9 - Reflected Cross-Site Scripting

Sep 27, 2021 Patched in 1.3.10 (848d)
Code Analysis
Analyzed Mar 16, 2026

WP Table Builder – Drag & Drop Table Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
11 prepared
Unescaped Output
5
79 escaped
Nonce Checks
0
Capability Checks
4
File Operations
10
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared11 total queries

Output Escaping

94% escaped84 total outputs
Attack Surface

WP Table Builder – Drag & Drop Table Builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wptb] inc\Core\Shortcode.php:11
WordPress Hooks 12
actionrest_api_initinc\Admin\Api\ApiHandler.php:12
filterposts_whereinc\Admin\Api\TableGet.php:87
actiontemplate_redirectinc\Core\Cpt.php:59
filterthe_contentinc\Core\Cpt.php:78
filterupgrader_package_optionsinc\Core\VersionControl.php:148
actionenqueue_block_editor_assetsinc\Utils\Assets.php:15
actionadmin_print_footer_scriptsinc\Utils\Assets.php:19
actionadmin_enqueue_scriptsinc\Utils\Assets.php:89
actionwp_footerinc\Utils\AssetsFrontend.php:32
actioninitwp-table-builder.php:67
actionadmin_menuwp-table-builder.php:72
actionadmin_bar_menuwp-table-builder.php:78
Maintenance & Trust

WP Table Builder – Drag & Drop Table Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version7.4
Downloads2.1M

Community Trust

Rating96/100
Number of ratings678
Active installs50K
Developer Profile

WP Table Builder – Drag & Drop Table Builder Developer Profile

WP Table Builder

1 plugin · 50K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
131 days
View full developer profile
Detection Fingerprints

How We Detect WP Table Builder – Drag & Drop Table Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-table-builder/src/editor-common.ts/wp-content/plugins/wp-table-builder/src/editor.scss/wp-content/plugins/wp-table-builder/src/styles.scss/wp-content/plugins/wp-table-builder/src/frontend/common.ts/wp-content/plugins/wp-table-builder/build/index.js/wp-content/plugins/wp-table-builder/build/editor.css/wp-content/plugins/wp-table-builder/src/index.tsx
Script Paths
/wp-content/plugins/wp-table-builder/dist/@vite/client/wp-content/plugins/wp-table-builder/dist/@react-refresh/wp-content/plugins/wp-table-builder/dist/src/editor-common.ts/wp-content/plugins/wp-table-builder/dist/src/frontend/common.ts/wp-content/plugins/wp-table-builder/dist/build/index.js/wp-content/plugins/wp-table-builder/dist/src/index.tsx
Version Parameters
?v=2.1.10

HTML / DOM Fingerprints

Data Attributes
data-wp-table-builder-settings
JS Globals
WPTB_CFG
REST Endpoints
/wp-json/wp-table-builder/
FAQ

Frequently Asked Questions about WP Table Builder – Drag & Drop Table Builder