PatchSiren

FlexTable CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW FlexTable CVE published 2026-01-05

CVE-2025-9543

The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, allowing high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. This vulnerability requires immediate attention from WordPress administrators and security teams, especially those using the FlexTable plugin i [truncated]