plugin

Posts Table Filterable Vulnerabilities

19 known security issues reported for the Posts Table Filterable WordPress plugin. Most recent disclosed Aug 4, 2026.

1 critical 2 high 7 medium

Running Posts Table Filterable on your site? Check whether your installed version is affected.

Scan your site free

TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter

high

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient escaping on the user-supplied parameter an...

CVSS:
7.5
Affected:
up to 1.0.5.1
Fixed in:
1.0.6
Disclosed:
Aug 4, 2026

CVE-2026-18881 on NVD →

TableOn – WordPress Posts Table Filterable  <= 1.0.5.1 - Unauthenticated SQL Injection

high

The TableOn – WordPress Posts Table Filterable  plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...

CVSS:
7.5
Affected:
up to 1.0.5.1
Fixed in:
1.0.6
Disclosed:
May 30, 2026

CVE-2026-42755 on NVD →

TableOn – WordPress Posts Table Filterable <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute

medium

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode in all versions up to and including 1.0.4.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'class', 'help...

CVSS:
6.4
Affected:
up to 1.0.4.4
Fixed in:
1.0.5
Disclosed:
Apr 7, 2026

CVE-2026-3513 on NVD →

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] <= 1.0.4.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn posts-table-filterable allows Reflected XSS.This issue affects TableOn: from n/a through <= 1.0.4.2.

Affected:
up to 1.0.4.2
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-69316 on NVD →

TableOn <= 1.0.4.2 - Reflected Cross-Site Scripting

medium

The TableOn plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 1.0.4.2
Fixed in:
1.0.4.3
Disclosed:
Jan 20, 2026

CVE-2025-69316 on NVD →

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] <= 1.0.4.2 (unfixed)

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RealMag777 TableOn posts-table-filterable allows Code Injection.This issue affects TableOn: from n/a through <= 1.0.4.2.

Affected:
up to 1.0.4.2
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-60244 on NVD →

TableOn – WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode

medium

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tableon_popup_iframe_button shortcode in all versions up to, and including, 1.0.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...

CVSS:
6.4
Affected:
up to 1.0.4.1
Fixed in:
1.0.4.2
Disclosed:
Jun 20, 2025

CVE-2025-5143 on NVD →

TableOn <= 1.0.5.1 - Unauthenticated Arbitrary Shortcode Execution

medium

The The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.5.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possibl...

CVSS:
6.5
Affected:
up to 1.0.5.1
Fixed in:
1.0.6
Disclosed:
May 22, 2025

CVE-2025-60244 on NVD →

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] < 1.0.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Stored XSS. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.3.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Apr 17, 2025

CVE-2025-32592 on NVD →

TableOn – WordPress Posts Table Filterable <= 1.0.3 - Unauthenticated Stored Cross-Site Scripting

medium

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
6.1
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Apr 14, 2025

CVE-2025-32592 on NVD →

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] <= 1.0.4 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Object Injection. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.2.

Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Apr 11, 2025

CVE-2025-32569 on NVD →

TableOn – WordPress Posts Table Filterable <= 1.0.4.3 - Unauthenticated PHP Object Injection

critical

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.4.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable softwar...

CVSS:
9.8
Affected:
up to 1.0.4.3
Fixed in:
1.0.4.4
Disclosed:
Apr 10, 2025

CVE-2025-32569 on NVD →

TableOn – WordPress Posts Table Filterable <= 1.0.5.1 - Missing Authorization

medium

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized a...

CVSS:
4.3
Affected:
up to 1.0.5.1
Fixed in:
1.0.6
Disclosed:
Apr 4, 2025

CVE-2025-32218 on NVD →

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] <= 1.0.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.4.

Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32218 on NVD →

TableOn – WordPress Posts Table Filterable <= 1.0.0 - Reflected Cross-Site Scripting

medium

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tableon-remote-page’ parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...

CVSS:
6.1
Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Oct 18, 2021

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] < 1.0.1

unknown

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tableon-remote-page’ parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Oct 18, 2021

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] < 1.0.1

unknown

Reflected Cross-Scripting (XSS) vulnerability discovered in WordPress TableOn – WordPress Posts Table Filterable plugin (versions <= 1.0.0).

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Sep 29, 2021

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] < 1.0.4.2

unknown
Affected:
up to 1.0.4.2
Fixed in:
1.0.4.2

CVE-2025-5143 on NVD →

TableOn &#8211; WordPress Posts Table Filterable  [posts-table-filterable] < 1.0.1

unknown

The plugin does not sanitise or escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting issues

Affected:
up to 1.0.1
Fixed in:
1.0.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database