CVE-2025-30944

7.5

Essekia · Tablesome Table Premium

A missing authorization vulnerability in the Tablesome Table Premium plugin allows unauthorized users to access restricted functionality, potentially leading to unauthorized data modification.

Executive summary

The Essekia Tablesome Table Premium plugin is vulnerable to a missing authorization flaw that allows unauthenticated attackers to perform unauthorized actions, posing a significant risk to data integrity.

Vulnerability

This vulnerability is caused by a missing authorization check (CWE-862), which allows an unauthenticated attacker to interact with plugin functions that lack proper access control lists.

Business impact

The lack of authorization controls allows unauthenticated actors to potentially manipulate or modify data within the tables managed by the plugin. With a CVSS score of 7.5, this high-severity vulnerability could lead to unauthorized data changes or administrative disruption, resulting in significant operational impact and loss of trust in the integrity of stored information.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should monitor the official Patchstack advisory and the vendor website for the release of an updated version. If the plugin is not mission-critical, consider deactivating it until a secure version is available.

Proactive Monitoring: Review web server and application access logs for unusual requests directed at plugin-specific endpoints, particularly those originating from unauthorized or external IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting the plugin's administrative or functional endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the ease of exploitation for unauthenticated users, this vulnerability requires immediate attention. Security teams should prioritize identifying all instances of the affected plugin within their environment and prepare to update immediately upon the vendor release of a security patch. Until then, restrict network access to the affected web application where possible to minimize exposure.

More Essekia CVEs

Sources

Originally found and disclosed by Jamie Davies | Patchstack Bug Bounty Program, per the CVE Program record.