Junglewise Threat Intelligence

CVE-2026-66659: Essekia Tablesome Table SQL injection

CVE-2026-66659 · Severity: critical · CVSS 9.3 · Published 2026-08-12

Executive brief

Tablesome Table is a WordPress plugin used to create and manage data tables on websites. An unauthenticated attacker can exploit an SQL injection vulnerability to read, modify, or delete entire databases, including user credentials and customer data, potentially compromising the security of thousands of websites simultaneously.

Technical details

This is an unauthenticated SQL injection vulnerability in the Essekia Tablesome Table WordPress plugin (versions through 1.2.12). The plugin fails to properly sanitize user input before incorporating it into SQL queries, allowing attackers to inject arbitrary SQL commands. The vulnerability is remotely exploitable over the network without requiring authentication or user interaction. A successful exploit grants attackers the ability to read sensitive data, modify database records, or delete entire databases. The vulnerability is patched in version 1.2.13 and later.

Affected products

  • Essekia Tablesome Table through 1.2.12

Timeline

  • 2026-04-21: disclosed: Reported to Patchstack
  • 2026-08-11: advisory: Published by Patchstack
  • 2026-08-11: patched: Fix available in version 1.2.13 and later

References