Impact
The vulnerability arises from improper neutralization of special elements in an SQL command within the Essekia Tablesome Table WordPress plugin. This can be exploited to perform Blind SQL Injection, allowing an attacker to read, modify, or delete data stored in the database without direct visibility of query results. The impact is the loss of data confidentiality, integrity, or availability depending on the attacker’s objectives.
Affected Systems
All installations of the Essekia Tablesome Table plugin at version 1.2.9 or earlier are affected. The vulnerability does not impact later releases of the plugin.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity level. While the EPSS score is not available, the absence of a CISA KEV listing suggests that no widespread active exploitation has been reported publicly. The exploit is remote and does not require local privileges; an attacker only needs to craft a malicious payload that reaches the vulnerable plugin endpoint, which is typically exposed on publicly accessible WordPress sites. The blind nature of the injection means that an attacker may need to perform time‑based or inference‑based techniques to enumerate data, but once the ROC is achieved, the attacker can gain significant control over the database.
OpenCVE Enrichment