Arbitrary File Upload Vulnerability in Tablesome Table Plugin by WordPress
CVE-2025-11499

9.8CRITICAL

What is CVE-2025-11499?

The Tablesome Table plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to insufficient file type validation in the set_featured_image_from_external_url() function. This flaw exists across all versions up to and including 1.1.32, enabling unauthenticated attackers to upload arbitrary files to the server. The vulnerability poses a significant risk, particularly in configurations where unauthenticated users can add featured images, leading to potential remote code execution under exploitation.

Affected Version(s)

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent * <= 1.1.32

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Talal Nasraddeen
.
CVE-2025-11499 : Arbitrary File Upload Vulnerability in Tablesome Table Plugin by WordPress