PT-2025-45285 · Realmag777+1 · Tableon+1

CVE-2025-60244

·

Published

2025-05-22

·

Updated

2025-11-06

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions TableOn versions prior to 1.0.5.2
Description An issue exists in the TableOn plugin that allows for code injection and arbitrary shortcode execution. This occurs because the software fails to properly validate values before executing the do shortcode() function, enabling unauthenticated attackers to execute arbitrary shortcodes through improper neutralization of script-related HTML tags.
Recommendations Update to a version newer than 1.0.5.1.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60244

Affected Products

Tableon
Posts-Table-Filterable