Executive brief
Tablesome Table is a WordPress plugin used to create and manage data tables on websites. An unauthenticated attacker can exploit an SQL injection vulnerability to read, modify, or delete entire databases, including user credentials and customer data, potentially compromising the security of thousands of websites simultaneously.
Technical details
This is an unauthenticated SQL injection vulnerability in the Essekia Tablesome Table WordPress plugin (versions through 1.2.12). The plugin fails to properly sanitize user input before incorporating it into SQL queries, allowing attackers to inject arbitrary SQL commands. The vulnerability is remotely exploitable over the network without requiring authentication or user interaction. A successful exploit grants attackers the ability to read sensitive data, modify database records, or delete entire databases. The vulnerability is patched in version 1.2.13 and later.
Affected products
- Essekia Tablesome Table through 1.2.12
Timeline
- 2026-04-21: disclosed: Reported to Patchstack
- 2026-08-11: advisory: Published by Patchstack
- 2026-08-11: patched: Fix available in version 1.2.13 and later