CyberRota Analysis
AI-GeneratedThe TableOn – WordPress Posts Table Filterable plugin is vulnerable to blind SQL Injection through the `filter_data[comment_count]` parameter, allowing unauthenticated attackers to manipulate SQL queries and potentially extract sensitive database information. This vulnerability arises from inadequate input sanitization and SQL query preparation, making it critical for all WordPress users utilizing this plugin, especially those managing sensitive data, to prioritize immediate updates to version 1.0.5.1 or later.
Original NVD Description
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query — the value is split on `:` and both halves are interpolated directly into a `posts_where` SQL clause without `intval()` casting or `$wpdb->prepare()`. This makes it possible for unauthenticated attackers to append additional SQL queries into the already-existing query that can be used to extract sensitive information from the database (researcher demonstrated extraction of database(), wp_users.user_login, and wp_users.user_pass).