Description
WordPress Plugin TablePress is prone to an XML External Entity injection vulnerability. Attackers can exploit this issue to gain access to sensitive information or cause Denial-of-Service condition. WordPress Plugin TablePress version 1.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.1 or latest
References
http://jvn.jp/en/jp/JVN05398317/index.html
https://plugins.svn.wordpress.org/tablepress/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin GenerateBlocks Cross-Site Scripting (1.3.5)
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress CSV Injection (1.4.7)
WordPress Plugin WP Meta and Date Remover Cross-Site Request Forgery (1.7.5)
WordPress Plugin VO Store Locator-WP Store Locator Unspecified Vulnerability (3.2.14)