
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27373 is a Blind SQL Injection vulnerability in the Essekia Tablesome WordPress plugin, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the Tablesome plugin up to and including 1.2.3, with version 1.2.4 being the patched release. The vulnerability was reported on November 22, 2025, by researcher 'daroo' and published by Patchstack on February 24, 2026. It carries a CVSS v3.1 base score of 8.5 (High) (Patchstack).
The vulnerability stems from insufficient sanitization of user-supplied input in SQL queries within the Tablesome WordPress plugin, allowing an attacker to inject malicious SQL syntax (CWE-89). The attack vector is network-based, requires only low privileges (Subscriber-level access), no user interaction, and has low attack complexity, making it accessible to a broad range of attackers. The exploitation technique is Blind SQL Injection (CAPEC-7), meaning the attacker infers database contents through boolean-based or time-based responses rather than direct output. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows a low-privileged attacker to extract sensitive data from the WordPress database, including user credentials, personal information, and site configuration data, resulting in high confidentiality impact. The scope is changed, meaning the impact can extend beyond the plugin itself to the broader WordPress database. Availability can also be degraded through resource-intensive blind SQL injection queries, though integrity is not directly impacted (Patchstack).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been observed as of the time of publication. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No threat actor attribution or CISA KEV catalog listing has been identified (Patchstack).
' AND SLEEP(5)-- or ' AND 1=1--) into the vulnerable parameter to confirm exploitability based on server response time or behavior differences.sqlmap with the identified vulnerable parameter to enumerate databases, tables, and extract sensitive data (e.g., WordPress wp_users table containing hashed passwords).', --, SLEEP(), WAITFOR DELAY) in query parameters; time-delayed responses from the web server suggesting time-based blind SQL injection.SLEEP, BENCHMARK, or boolean logic patterns in database slow query logs.The primary remediation is to update the Tablesome plugin to version 1.2.4 or later, which contains the fix for this vulnerability (Patchstack). If an immediate update is not possible, site administrators should consider disabling or removing the Tablesome plugin until patching can be performed. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts without requiring a plugin update. Additionally, restricting Subscriber-level user registration on the WordPress site can reduce the attack surface.
Patchstack, which discovered and disclosed the vulnerability through researcher 'daroo', classifies it as high priority and warns it is the type of vulnerability commonly leveraged in mass WordPress exploit campaigns. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."