Description
Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.2.6.
Published: 2026-01-23
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in the Essekia Tablesome WordPress plugin (versions up to 1.2.6) stems from missing authorization checks. An attacker who can invoke the plugin’s functions is able to bypass the intended access restrictions, potentially executing actions that should be limited to privileged users. The result is unauthorized access to the plugin’s data or configuration, which could lead to data disclosure or modification. The weakness corresponds to CWE‑862 – Missing Authorization.

Affected Systems

Essekia Tablesome plugin for WordPress, all released versions up to and including 1.2.6.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1 % suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, meaning no confirmed exploitation has been reported during reconnaissance. Attackers could exploit the flaw from a remote web session by sending crafted HTTP requests to the plugin’s endpoints that lack proper authorization checks. Once the exploit succeeds, the attacker can perform privileged actions such as reading, editing, or deleting data managed by Tablesome.

Generated by OpenCVE AI on April 16, 2026 at 01:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Essekia Tablesome plugin to a version newer than 1.2.6, where the missing authorization checks have been corrected.
  • Ensure that WordPress user accounts accessing the plugin have the least privilege required, and consider removing or disabling the Tablesome plugin for accounts that do not need it.
  • Monitor the website’s access logs for unusual activity or requests targeting the Tablesome endpoint, and block suspicious patterns if necessary.

Generated by OpenCVE AI on April 16, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.1.35.2. Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.2.6.
Title WordPress Tablesome plugin <= 1.1.35.2 - Broken Access Control vulnerability WordPress Tablesome plugin <= 1.2.6 - Broken Access Control vulnerability

Mon, 26 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 23 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.1.35.2.
Title WordPress Tablesome plugin <= 1.1.35.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:14:13.171Z

Reserved: 2026-01-23T12:31:31.583Z

Link: CVE-2026-24524

cve-icon Vulnrichment

Updated: 2026-01-26T19:37:29.126Z

cve-icon NVD

Status : Deferred

Published: 2026-01-23T15:16:08.200

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-24524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T02:00:12Z

Weaknesses