cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcodepress-admin-columns codepress-admin-columns

Direction: descending
Jun 07, 2026

Admin Columns # CVE-2026-7654

CVE, Research URL

CVE-2026-7654

Application

Admin Columns

Date
Jun 06, 2026
Research Description
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` function, which processes attacker-controlled post meta values without proper validation. This makes it possible for authenticated attackers with Contributor-level access and above to inject a serialized PHP object into a post's custom meta field and trigger arbitrary code execution by exploiting a bundled POP gadget chain, resulting in remote code execution as the web server user.
Affected versions
max 7.0.19.
Status
vulnerable
Jun 07, 2024

Admin Columns # CVE-2019-17661

CVE, Research URL

CVE-2019-17661

Application

Admin Columns

Date
Nov 08, 2019
Research Description
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
Affected versions
max 3.4.6.
Status
vulnerable

Admin Columns # CVE-2021-24366

CVE, Research URL

CVE-2021-24366

Application

Admin Columns

Date
Jun 22, 2021
Research Description
The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 4.3.
Status
vulnerable

Admin Columns # CVE-2021-24365

CVE, Research URL

CVE-2021-24365

Application

Admin Columns

Date
Jul 13, 2021
Research Description
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.
Affected versions
max 4.3.2.
Status
vulnerable