Junglewise Threat Intelligence

CVE-2026-24582: WPPOOL FlexTable missing authorization in access control settings

CVE-2026-24582 · Severity: medium · CVSS 4.3 · Published 2026-05-25

Executive brief

WPPOOL FlexTable is a WordPress plugin used to sync and display data from spreadsheets as live tables on a website. A security flaw in the plugin's access control settings allows users with low-level permissions (such as contributors) to perform actions they should not be authorized to do. This could lead to unauthorized modifications of table data or settings, potentially impacting the integrity of information displayed on the site.

Technical details

A missing authorization vulnerability (CWE-862) exists in the WPPOOL FlexTable plugin (also known as Sheets to WP Table Live Sync) for WordPress through version 3.24.0. The flaw resides in the plugin's failure to properly validate user permissions before executing certain functions, allowing an attacker with 'Contributor' level privileges or higher to bypass intended access controls. By exploiting this misconfiguration, a remote authenticated attacker can perform unauthorized actions that should be restricted to higher-privileged roles. As of the advisory date, no official patch has been released, and users are advised to monitor for updates or restrict plugin access.

Affected products

  • WPPOOL FlexTable (Sheets to WP Table Live Sync) n/a through 3.24.0

Timeline

  • 2025-12-20: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-05-25: advisory: Advisory published by Patchstack and NVD

References