CVE-2026-27373
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27373 is a Blind SQL Injection vulnerability in the Essekia Tablesome WordPress plugin, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the Tablesome plugin up to and including 1.2.3, with version 1.2.4 being the patched release. The vulnerability was reported on November 22, 2025, by researcher 'daroo' and published by Patchstack on February 24, 2026. It carries a CVSS v3.1 base score of 8.5 (High) (Patchstack).

Technical details

The vulnerability stems from insufficient sanitization of user-supplied input in SQL queries within the Tablesome WordPress plugin, allowing an attacker to inject malicious SQL syntax (CWE-89). The attack vector is network-based, requires only low privileges (Subscriber-level access), no user interaction, and has low attack complexity, making it accessible to a broad range of attackers. The exploitation technique is Blind SQL Injection (CAPEC-7), meaning the attacker infers database contents through boolean-based or time-based responses rather than direct output. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows a low-privileged attacker to extract sensitive data from the WordPress database, including user credentials, personal information, and site configuration data, resulting in high confidentiality impact. The scope is changed, meaning the impact can extend beyond the plugin itself to the broader WordPress database. Availability can also be degraded through resource-intensive blind SQL injection queries, though integrity is not directly impacted (Patchstack).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been observed as of the time of publication. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No threat actor attribution or CISA KEV catalog listing has been identified (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Tablesome plugin version 1.2.3 or earlier using tools like WPScan, Shodan, or Google dorks targeting plugin-specific file paths.
  2. Obtain low-privilege access: Register or obtain Subscriber-level credentials on the target WordPress site, as the vulnerability requires at minimum low privileges.
  3. Identify the vulnerable parameter: Interact with Tablesome plugin functionality and intercept HTTP requests using a proxy tool (e.g., Burp Suite) to identify parameters passed to SQL queries.
  4. Craft blind SQL injection payload: Inject boolean-based or time-based SQL payloads (e.g., ' AND SLEEP(5)-- or ' AND 1=1--) into the vulnerable parameter to confirm exploitability based on server response time or behavior differences.
  5. Extract database contents: Use automated tools such as sqlmap with the identified vulnerable parameter to enumerate databases, tables, and extract sensitive data (e.g., WordPress wp_users table containing hashed passwords).
  6. Escalate access: Use extracted credentials (after cracking password hashes) to escalate to administrator-level access and achieve full site compromise (Patchstack).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to Tablesome plugin endpoints containing SQL metacharacters (e.g., single quotes ', --, SLEEP(), WAITFOR DELAY) in query parameters; time-delayed responses from the web server suggesting time-based blind SQL injection.
  • Logs: WordPress or web server access logs showing repeated requests from a single low-privilege user account to Tablesome-related endpoints with anomalous parameter values; database error messages logged related to malformed SQL queries.
  • Database: Unexpected or high-volume database query activity originating from the WordPress application user; queries containing SLEEP, BENCHMARK, or boolean logic patterns in database slow query logs.

Mitigation and workarounds

The primary remediation is to update the Tablesome plugin to version 1.2.4 or later, which contains the fix for this vulnerability (Patchstack). If an immediate update is not possible, site administrators should consider disabling or removing the Tablesome plugin until patching can be performed. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts without requiring a plugin update. Additionally, restricting Subscriber-level user registration on the WordPress site can reduce the attack surface.

Community reactions

Patchstack, which discovered and disclosed the vulnerability through researcher 'daroo', classifies it as high priority and warns it is the type of vulnerability commonly leveraged in mass WordPress exploit campaigns. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified at this time (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-3174HIGH7.5
  • event-tickets
NoYesSep 08, 2026
CVE-2026-18021MEDIUM6.5
  • beaver-builder-lite-version
NoYesSep 08, 2026
CVE-2026-17509MEDIUM6.5
  • sitepress-multilingual-cms
NoYesSep 08, 2026
CVE-2026-76931MEDIUM6.4
  • zephyr-project-manager
NoYesSep 08, 2026
CVE-2026-2520MEDIUM5.4
  • bookly-responsive-appointment-booking-tool
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management