LOW
FlexTable
CVE published 2026-01-05
CVE-2025-9543
The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, allowing high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. This vulnerability requires immediate attention from WordPress administrators and security teams, especially those using the FlexTable plugin i [truncated]