Impact
The RealMag777 TableOn posts‑table‑filterable plugin contains a deserialization vulnerability (CWE‑502). The plugin accepts data from users and deserializes it, allowing an attacker to inject arbitrary PHP objects. If exploited, these objects can execute code on the server, compromising confidentiality, integrity and availability of the WordPress installation.
Affected Systems
Version 1.0.4.3 and earlier of TableOn posts‑table‑filterable from RealMag777 are affected. All sites running these versions are vulnerable until updated.
Risk and Exploitability
The vulnerability scores a CVSS of 9.8, indicating critical impact. The EPSS score is below 1 %, suggesting exploitation is unlikely to be widespread yet the risk remains high if an attacker manages to reach the plugin. The plugin is web‑based, so the likely attack vector is an HTTP request carrying malicious serialized data. The vulnerability is not listed in CISA KEV, meaning no known active exploits have been reported.
OpenCVE Enrichment
EUVD