CVE-2025-2685

TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 86,377 live websites that are affected by CVE-2025-2685.

Run a Free Instant Scan




Affected Software

Product  TablePress
Category Wordpress Plugins
Vulnerable Domains86,377 live websites (44% of TablePress install base)
Vulnerable Versions
  • from 0 through 3.0.4
Vulnerable Versions Count55 versions ( 85% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Mar 27, 2025
  • Updated - Mar 27, 2025

Credits

  • SavPhill (finder)

Website Distribution by Country

Number of websites using CVE-2025-2685
United States17,045 websites



Japan11,707 websites
Germany10,897 websites
Russia5,527 websites
France4,712 websites
GB3,496 websites
Italy3,023 websites
Netherlands2,326 websites
Poland2,147 websites
Canada1,346 websites

Website Distribution by TLD

Number of websites using CVE-2025-2685
.com28,951 websites
.de7,356 websites
.ru4,620 websites
.org4,609 websites
.net2,809 websites
.jp2,476 websites
.it2,192 websites
.fr2,189 websites
.nl2,066 websites
.co.uk2,039 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-2685

Top websites that are affected by CVE-2025-2685. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org United States***
****.br Brazil***
*****.net Singapore***
****.******.com Singapore***
******.de Germany*,***
*******.org United States*,***
***.org United States*,***
*********.me United States*,***
*****.com United States*,***
***.***.edu United States*,***
See full domain list

FAQ

CVE-2025-2685 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TablePress
A total of 86,377 websites have been identified as vulnerable to CVE-2025-2685, based on global website indexing conducted by WebTechSurvey.
The TablePress is affected by the CVE-2025-2685 vulnerability.
TablePress versions up to and including 3.0.4 are vulnerable to CVE-2025-2685.