Executive brief
The BuddyHolis TableSearch plugin for WordPress, which allows users to add search functionality to tables, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will run automatically whenever any visitor, including site administrators, views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'placeholder' parameter. This vulnerability exists in all versions up to and including 1.1.0. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into the plugin's settings or shortcodes. Because the payload is stored on the server, the script executes in the browser of any user who visits the affected page. The attack requires network access and low-level authentication but no specific user interaction beyond the victim viewing the page.
Affected products
- digiblogger BuddyHolis TableSearch All versions up to, and including, 1.1.0
Timeline
- 2026-07-10: disclosed: CVE published by Wordfence/NVD