{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/tableon--wordpress-posts-table-filterable--1.0.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18881"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TableOn – WordPress Posts Table Filterable (\u003c= 1.0.5.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe TableOn - WordPress Posts Table Filterable plugin for WordPress is vulnerable to a blind SQL injection vulnerability identified as CVE-2026-18881. This flaw affects all versions up to and including 1.0.5.1. The vulnerability exists within the public \u003ccode\u003etableon_get_table_data\u003c/code\u003e AJAX action, specifically due to improper handling of the \u003ccode\u003efilter_data[comment_count]\u003c/code\u003e parameter. The plugin fails to apply necessary input validation or sanitization, such as \u003ccode\u003eintval()\u003c/code\u003e casting, and fails to use the \u003ccode\u003e$wpdb-\u0026gt;prepare()\u003c/code\u003e function when processing this parameter. Consequently, the input is interpolated directly into a \u003ccode\u003eposts_where\u003c/code\u003e SQL clause after being split by a colon delimiter. Unauthenticated attackers can leverage this flaw to append malicious SQL commands, enabling them to execute blind SQL injection attacks to exfiltrate sensitive data from the WordPress database, including entries from the \u003ccode\u003ewp_users\u003c/code\u003e table.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to perform blind SQL injection against the host WordPress site. Potential consequences include the exfiltration of sensitive information, such as administrator hashes or user credentials, which could lead to complete site compromise. Given the prevalence of WordPress plugins in enterprise environments, this poses a high risk to sites utilizing the TableOn plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the TableOn - WordPress Posts Table Filterable plugin to the latest version released after August 5, 2026, which contains the security patch for CVE-2026-18881.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block incoming HTTP requests targeting the \u003ccode\u003etableon_get_table_data\u003c/code\u003e action where the \u003ccode\u003efilter_data[comment_count]\u003c/code\u003e parameter contains SQL-specific characters or patterns.\u003c/li\u003e\n\u003cli\u003eAudit database query logs for suspicious patterns originating from external IP addresses targeting the affected AJAX endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T11:15:39Z","date_published":"2026-08-05T11:15:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tableon-sqli/","summary":"An unauthenticated SQL injection vulnerability in the TableOn WordPress plugin allows attackers to extract sensitive database information via the filter_data[comment_count] parameter.","title":"CVE-2026-18881: SQL Injection in TableOn WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-tableon-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - TableOn – WordPress Posts Table Filterable (\u003c= 1.0.5.1)","version":"https://jsonfeed.org/version/1.1"}