Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.

This issue affects Tablesome Table: from n/a through 1.2.9.
Published: 2026-08-12
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of special elements in an SQL command within the Essekia Tablesome Table WordPress plugin. This can be exploited to perform Blind SQL Injection, allowing an attacker to read, modify, or delete data stored in the database without direct visibility of query results. The impact is the loss of data confidentiality, integrity, or availability depending on the attacker’s objectives.

Affected Systems

All installations of the Essekia Tablesome Table plugin at version 1.2.9 or earlier are affected. The vulnerability does not impact later releases of the plugin.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity level. While the EPSS score is not available, the absence of a CISA KEV listing suggests that no widespread active exploitation has been reported publicly. The exploit is remote and does not require local privileges; an attacker only needs to craft a malicious payload that reaches the vulnerable plugin endpoint, which is typically exposed on publicly accessible WordPress sites. The blind nature of the injection means that an attacker may need to perform time‑based or inference‑based techniques to enumerate data, but once the ROC is achieved, the attacker can gain significant control over the database.

Generated by OpenCVE AI on August 12, 2026 at 12:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Tablesome Table version 1.3.0 or later to apply the vendor fix that properly sanitizes user input.
  • If an upgrade is not immediately possible, disable or remove the vulnerable plugin to eliminate the attack surface.
  • Apply strict database privilege policies, ensuring that the web application uses the least privilege account and monitor database logs for anomalous queries driven by injection attempts.

Generated by OpenCVE AI on August 12, 2026 at 12:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Essekia
Essekia tablesome Table
Wordpress
Wordpress wordpress
Vendors & Products Essekia
Essekia tablesome Table
Wordpress
Wordpress wordpress

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.
Title WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Essekia Tablesome Table
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-12T16:57:13.035Z

Reserved: 2026-07-27T14:00:43.007Z

Link: CVE-2026-66659

cve-icon Vulnrichment

Updated: 2026-08-12T14:58:55.880Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T06:22:09.420

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-66659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:45:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')