← WordPress Vulnerabilities
WordPress security by component

TableOn – WordPress Posts Table Filterable

TableOn – WordPress Posts Table Filterable is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.8.

Plugin slug: posts-table-filterable

CVE-2026-18881: TableOn public comment_count filter permits blind SQL injection

TableOn through 1.0.5.1 exposes the tableon_get_table_data AJAX action to unauthenticated callers. The filter_data[comment_count] value is split on a colon and both attacker-controlled halves are interpolated directly into a posts_where clause without integer conversion or $wpdb->prepare(). An attacker can perform blind SQL injection and extract sensitive database contents; the researcher demonstrated database(), wp_users.user_login and wp_users.user_pass extraction. The CNA does not disclose the callback name or complete query.

PublishedAug 05, 2026
Known safe version> 1.0.5.1
Published vulnerabilities for posts-table-filterable
Safe version
Aug 05, 2026 CVE-2026-18881
TableOn public comment_count filter permits blind SQL injection
TableOn through 1.0.5.1 exposes the tableon_get_table_data AJAX action to unauthenticated callers. The filter_data[comment_count] value is split on a colon and both attacker-controlled halves are interpolated directly into a posts_where clause without integer conversion or $wpdb->prepare(). An attacker can perform blind SQL injection and extract sensitive database contents; the researcher demonstrated database(), wp_users.user_login and wp_users.user_pass extraction. The CNA does not disclose the callback name or complete query.
> 1.0.5.1
CVE7.5
NVDPending
May 27, 2026 CVE-2026-42755
TableOn: SQL injection
TableOn is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.0.5.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
1.0.6
CVE9.3
NVDPending
Apr 08, 2026 CVE-2026-3513
TableOn – WordPress Posts Table Filterable: Cross-site scripting
TableOn – WordPress Posts Table Filterable is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.0.4.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVDPending
Jan 22, 2026 CVE-2025-69316
TableOn: Cross-site scripting
TableOn is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.1
NVDPending
Nov 06, 2025 CVE-2025-60244
TableOn: Cross-site scripting
TableOn is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.1
NVDPending
Jun 21, 2025 CVE-2025-5143
TableOn – WordPress Posts Table Filterable: Cross-site scripting
TableOn – WordPress Posts Table Filterable is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVD5.4
Apr 17, 2025 CVE-2025-32592
TableOn: Cross-site scripting
TableOn is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.1
NVDPending
Apr 11, 2025 CVE-2025-32569
TableOn: Code execution
TableOn is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.8
NVDPending
Apr 04, 2025 CVE-2025-32218
TableOn: A security weakness
TableOn is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVDPending