Description
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.This issue affects TableOn: from n/a through <= 1.0.4.3.
Published: 2025-04-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The RealMag777 TableOn posts‑table‑filterable plugin contains a deserialization vulnerability (CWE‑502). The plugin accepts data from users and deserializes it, allowing an attacker to inject arbitrary PHP objects. If exploited, these objects can execute code on the server, compromising confidentiality, integrity and availability of the WordPress installation.

Affected Systems

Version 1.0.4.3 and earlier of TableOn posts‑table‑filterable from RealMag777 are affected. All sites running these versions are vulnerable until updated.

Risk and Exploitability

The vulnerability scores a CVSS of 9.8, indicating critical impact. The EPSS score is below 1 %, suggesting exploitation is unlikely to be widespread yet the risk remains high if an attacker manages to reach the plugin. The plugin is web‑based, so the likely attack vector is an HTTP request carrying malicious serialized data. The vulnerability is not listed in CISA KEV, meaning no known active exploits have been reported.

Generated by OpenCVE AI on April 30, 2026 at 23:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Immediately upgrade or uninstall the TableOn plugin; ensure the installation uses a version that contains the deserialization fix.
  • If removal is not immediately feasible, reconfigure or disable any plugin features that accept external serialized data, ensuring that user‑supplied input is never deserialized without strict validation.
  • Deploy a web application firewall or security plugin to block suspicious serialization payloads and monitor server logs for signs of attempted object injection.

Generated by OpenCVE AI on April 30, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10773 Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Object Injection. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Object Injection. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.2. Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.This issue affects TableOn: from n/a through <= 1.0.4.3.
Title WordPress TableOn Plugin <= 1.0.2 - PHP Object Injection vulnerability WordPress TableOn plugin <= 1.0.4.3 - PHP Object Injection vulnerability
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 11 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 09:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Object Injection. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.2.
Title WordPress TableOn Plugin <= 1.0.2 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:24.380Z

Reserved: 2025-04-09T11:20:09.347Z

Link: CVE-2025-32569

cve-icon Vulnrichment

Updated: 2025-04-11T13:31:13.075Z

cve-icon NVD

Status : Deferred

Published: 2025-04-11T09:15:28.827

Modified: 2026-04-23T15:29:07.657

Link: CVE-2025-32569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:15:05Z

Weaknesses