Impact
The vulnerability is a missing authorization flaw in the RealMag777 TableOn plugin for WordPress. It allows an attacker to access content or manage tables that should be restricted, leading to unauthorized disclosure or tampering of data. The weakness is classified as CWE‑862, which signifies that the system fails to check user permissions before performing privileged operations. No remote code execution or denial of service is reported, so the impact is limited to confidentiality and integrity of the accessed data.
Affected Systems
WordPress sites using the RealMag777 TableOn posts‑table‑filterable plugin version 1.0.5.1 or earlier are affected. This includes all installations of the plugin from the initial release through the specified maximum version. The plugin is identified in the database as RealMag777:TableOn.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation at this time; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted HTTP request to the plugin's endpoints that bypasses the authorization checks, an attack that can be carried out by an unauthenticated user or a user with limited privileges. Because the flaw permits direct access to restricted data, the exploitation could occur without any prerequisite code execution or privilege escalation, making it a straightforward path for attackers who discover the vulnerable query parameters.
OpenCVE Enrichment
EUVD