Executive brief
A security vulnerability exists in the TableOn WordPress plugin, which is used to create filterable tables of website posts. An attacker can exploit this flaw to gain unauthorized access to the website's database, potentially leading to the theft of sensitive information or disruption of services. This issue can be exploited remotely without requiring any user interaction or login credentials.
Technical details
The TableOn (posts-table-filterable) plugin for WordPress contains a Blind SQL Injection vulnerability due to improper neutralization of special elements used in SQL commands. The flaw exists in versions up to and including 1.0.5.1. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the affected component. Successful exploitation allows the attacker to extract sensitive data from the database through blind inference techniques. The CVSS score of 9.3 reflects the high impact on confidentiality and the lack of authentication requirements.
Affected products
- RealMag777 TableOn (posts-table-filterable) <= 1.0.5.1
Timeline
- 2026-05-27: disclosed: Vulnerability published in NVD dataset