VYPR

Tablesome Table

by WordPress

CVEs (3)

  • CVE-2025-11499CriNov 1, 2025
    risk 0.57cvss 9.8epss 0.01

    The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image_from_external_url() function in all versions up to, and including,…

  • CVE-2025-12845HigFeb 19, 2026
    risk 0.50cvss 8.8epss 0.00

    The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function in versions 0.5.4 to…

  • CVE-2026-14924HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.