TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter
high
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient escaping on the user-supplied parameter an...
- CVSS:
- 7.5
- Affected:
- up to 1.0.5.1
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 4, 2026
CVE-2026-18881 on NVD →
TableOn – WordPress Posts Table Filterable <= 1.0.5.1 - Unauthenticated SQL Injection
high
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.5
- Affected:
- up to 1.0.5.1
- Fixed in:
- 1.0.6
- Disclosed:
- May 30, 2026
CVE-2026-42755 on NVD →
TableOn – WordPress Posts Table Filterable <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute
medium
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode in all versions up to and including 1.0.4.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'class', 'help...
- CVSS:
- 6.4
- Affected:
- up to 1.0.4.4
- Fixed in:
- 1.0.5
- Disclosed:
- Apr 7, 2026
CVE-2026-3513 on NVD →
TableOn – WordPress Posts Table Filterable [posts-table-filterable] <= 1.0.4.2 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn posts-table-filterable allows Reflected XSS.This issue affects TableOn: from n/a through <= 1.0.4.2.
- Affected:
- up to 1.0.4.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-69316 on NVD →
TableOn <= 1.0.4.2 - Reflected Cross-Site Scripting
medium
The TableOn plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 1.0.4.2
- Fixed in:
- 1.0.4.3
- Disclosed:
- Jan 20, 2026
CVE-2025-69316 on NVD →
TableOn – WordPress Posts Table Filterable [posts-table-filterable] <= 1.0.4.2 (unfixed)
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RealMag777 TableOn posts-table-filterable allows Code Injection.This issue affects TableOn: from n/a through <= 1.0.4.2.
- Affected:
- up to 1.0.4.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-60244 on NVD →
TableOn – WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode
medium
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tableon_popup_iframe_button shortcode in all versions up to, and including, 1.0.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...
- CVSS:
- 6.4
- Affected:
- up to 1.0.4.1
- Fixed in:
- 1.0.4.2
- Disclosed:
- Jun 20, 2025
CVE-2025-5143 on NVD →
TableOn <= 1.0.5.1 - Unauthenticated Arbitrary Shortcode Execution
medium
The The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.5.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possibl...
- CVSS:
- 6.5
- Affected:
- up to 1.0.5.1
- Fixed in:
- 1.0.6
- Disclosed:
- May 22, 2025
CVE-2025-60244 on NVD →
TableOn – WordPress Posts Table Filterable [posts-table-filterable] < 1.0.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Stored XSS. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.3.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Apr 17, 2025
CVE-2025-32592 on NVD →
TableOn – WordPress Posts Table Filterable <= 1.0.3 - Unauthenticated Stored Cross-Site Scripting
medium
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.1
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Apr 14, 2025
CVE-2025-32592 on NVD →
TableOn – WordPress Posts Table Filterable [posts-table-filterable] <= 1.0.4 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Object Injection. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.2.
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 11, 2025
CVE-2025-32569 on NVD →
TableOn – WordPress Posts Table Filterable <= 1.0.4.3 - Unauthenticated PHP Object Injection
critical
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.4.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable softwar...
- CVSS:
- 9.8
- Affected:
- up to 1.0.4.3
- Fixed in:
- 1.0.4.4
- Disclosed:
- Apr 10, 2025
CVE-2025-32569 on NVD →
TableOn – WordPress Posts Table Filterable <= 1.0.5.1 - Missing Authorization
medium
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized a...
- CVSS:
- 4.3
- Affected:
- up to 1.0.5.1
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 4, 2025
CVE-2025-32218 on NVD →
TableOn – WordPress Posts Table Filterable [posts-table-filterable] <= 1.0.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.4.
- Affected:
- up to 1.0.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32218 on NVD →
TableOn – WordPress Posts Table Filterable <= 1.0.0 - Reflected Cross-Site Scripting
medium
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tableon-remote-page’ parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...
- CVSS:
- 6.1
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 18, 2021
TableOn – WordPress Posts Table Filterable [posts-table-filterable] < 1.0.1
unknown
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tableon-remote-page’ parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 18, 2021
TableOn – WordPress Posts Table Filterable [posts-table-filterable] < 1.0.1
unknown
Reflected Cross-Scripting (XSS) vulnerability discovered in WordPress TableOn – WordPress Posts Table Filterable plugin (versions <= 1.0.0).
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Sep 29, 2021
TableOn – WordPress Posts Table Filterable [posts-table-filterable] < 1.0.4.2
unknown
- Affected:
- up to 1.0.4.2
- Fixed in:
- 1.0.4.2
CVE-2025-5143 on NVD →
TableOn – WordPress Posts Table Filterable [posts-table-filterable] < 1.0.1
unknown
The plugin does not sanitise or escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database