The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 86,377 live websites that are affected by CVE-2025-2685.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 86,377 live websites (44% of TablePress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 55 versions ( 85% of all versions) |
| 17,045 websites | |
| 11,707 websites | |
| 10,897 websites | |
| 5,527 websites | |
| 4,712 websites | |
| 3,496 websites | |
| 3,023 websites | |
| 2,326 websites | |
| 2,147 websites | |
| 1,346 websites |
| .com | 28,951 websites |
| .de | 7,356 websites |
| .ru | 4,620 websites |
| .org | 4,609 websites |
| .net | 2,809 websites |
| .jp | 2,476 websites |
| .it | 2,192 websites |
| .fr | 2,189 websites |
| .nl | 2,066 websites |
| .co.uk | 2,039 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *** | ||
| ****.br | *** | ||
| *****.net | *** | ||
| ****.******.com | *** | ||
| ******.de | *,*** | ||
| *******.org | *,*** | ||
| ***.org | *,*** | ||
| *********.me | *,*** | ||
| *****.com | *,*** | ||
| ***.***.edu | *,*** |
FAQ