Impact
This vulnerability arises from improper neutralization of special characters in RealMag777’s TableOn posts-table-filterable component. An attacker can inject raw SQL through the plugin’s web interface, resulting in a blind SQL injection flaw (CWE-89). By manipulating query parameters, the attacker can read or modify data stored in the WordPress database, potentially exposing sensitive information or altering site content.
Affected Systems
Any WordPress site that has the TableOn plugin installed in a version through 1.0.5.1 is vulnerable. The vulnerability applies to every release from the earliest available version up to and including 1.0.5.1; sites using these versions should be considered at risk.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical. EPSS is not provided, so the current probability of exploitation cannot be quantified, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the blind SQL injection via the plugin’s exposed web endpoints, potentially extracting data or altering database contents. The high severity underscores the need for immediate attention to protect confidentiality and integrity of the WordPress installation.
OpenCVE Enrichment