AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18881

HIGH · CVSS 7.5 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The TableOn – WordPress Posts Table Filterable plugin is vulnerable to blind SQL Injection through the `filter_data[comment_count]` parameter, allowing unauthenticated attackers to manipulate SQL queries and potentially extract sensitive database information. This vulnerability arises from inadequate input sanitization and SQL query preparation, making it critical for all WordPress users utilizing this plugin, especially those managing sensitive data, to prioritize immediate updates to version 1.0.5.1 or later.

CVE
CVE-2026-18881
Severity
HIGH
CVSS
7.5
EPSS
0.38%
WordPress

Original NVD Description

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query — the value is split on `:` and both halves are interpolated directly into a `posts_where` SQL clause without `intval()` casting or `$wpdb->prepare()`. This makes it possible for unauthenticated attackers to append additional SQL queries into the already-existing query that can be used to extract sensitive information from the database (researcher demonstrated extraction of database(), wp_users.user_login, and wp_users.user_pass).