SQL Injection Vulnerability in Essekia Tablesome Plugin for WordPress
CVE-2026-66659
9.3CRITICAL
What is CVE-2026-66659?
An SQL Injection vulnerability exists in the Essekia Tablesome plugin for WordPress, allowing attackers to exploit improper neutralization of special elements in SQL commands. This flaw could lead to sensitive data exposure and manipulation. The vulnerability affects Tablesome Table versions from n/a through 1.2.9, posing a significant risk to websites using this plugin. Web administrators should apply available patches to mitigate this serious security issue.
Affected Version(s)
Tablesome Table <= 1.2.9
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Ba Khanh - HPT Vietnam Corporation | Patchstack Bug Bounty Program