TableOn – WordPress Posts Table Filterable
TableOn – WordPress Posts Table Filterable is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.8.
posts-table-filterableCVE-2026-18881: TableOn public comment_count filter permits blind SQL injection
TableOn through 1.0.5.1 exposes the tableon_get_table_data AJAX action to unauthenticated callers. The filter_data[comment_count] value is split on a colon and both attacker-controlled halves are interpolated directly into a posts_where clause without integer conversion or $wpdb->prepare(). An attacker can perform blind SQL injection and extract sensitive database contents; the researcher demonstrated database(), wp_users.user_login and wp_users.user_pass extraction. The CNA does not disclose the callback name or complete query.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-18881
TableOn public comment_count filter permits blind SQL injection
TableOn through 1.0.5.1 exposes the tableon_get_table_data AJAX action to unauthenticated callers. The filter_data[comment_count] value is split on a colon and both attacker-controlled halves are interpolated directly into a posts_where clause without integer conversion or $wpdb->prepare(). An attacker can perform blind SQL injection and extract sensitive database contents; the researcher demonstrated database(), wp_users.user_login and wp_users.user_pass extraction. The CNA does not disclose the callback name or complete query.
|
> 1.0.5.1 |
CVE7.5
NVDPending
|
| May 27, 2026 |
CVE-2026-42755
TableOn: SQL injection
TableOn is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.0.5.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
1.0.6 |
CVE9.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-3513
TableOn – WordPress Posts Table Filterable: Cross-site scripting
TableOn – WordPress Posts Table Filterable is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.0.4.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 22, 2026 |
CVE-2025-69316
TableOn: Cross-site scripting
TableOn is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Nov 06, 2025 |
CVE-2025-60244
TableOn: Cross-site scripting
TableOn is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jun 21, 2025 |
CVE-2025-5143
TableOn – WordPress Posts Table Filterable: Cross-site scripting
TableOn – WordPress Posts Table Filterable is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 17, 2025 |
CVE-2025-32592
TableOn: Cross-site scripting
TableOn is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Apr 11, 2025 |
CVE-2025-32569
TableOn: Code execution
TableOn is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32218
TableOn: A security weakness
TableOn is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVDPending
|