Extension WordPress

Vulnérabilités Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Cette page rassemble les failles publiées pour Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
1Critiques
14Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

14 fiches

CVE-2024-13362 Moyenne · 6,1
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-1.1.13

Correctif

1.1.17

Publication

30/04/2026

CVE-2026-27373 Moyenne · 6,5
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.2.3 – Authenticated (Subscriber+) SQL Injection

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and…

Versions affectées

*-1.2.3

Correctif

1.2.4

Publication

24/02/2026

CVE-2025-12845 Élevée · 8,8
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent 0.5.4 – 1.2.1 – Missing Authorization to Authenticated (Subscriber+) Information Exposure and Privilege Escalation

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function…

Versions affectées

0.5.4-1.2.1

Correctif

1.2.2

Publication

18/02/2026

CVE-2026-24524 Moyenne · 4,3
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Tablesome <= 1.2.8 – Missing Authorization

The Tablesome plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with subscriber-level access and above,…

Versions affectées

*-1.2.8

Correctif

1.2.9

Publication

26/01/2026

CVE-2025-68517 Moyenne · 4,3
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Tablesome <= 1.1.35.1 – Missing Authorization

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.35.1.…

Versions affectées

*-1.1.35.1

Correctif

1.1.35.2

Publication

22/12/2025

CVE-2025-68516 Moyenne · 6,5
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Tablesome <= 1.1.35.1 – Authenticated (Subscriber+) Information Exposure

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.35.1. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.1.35.1

Correctif

1.1.35.2

Publication

22/12/2025

CVE-2025-11499 Critique · 9,8
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 – Unauthenticated Arbitrary File Upload

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image_from_external_url() function in all versions up to, and…

Versions affectées

*-1.1.32

Correctif

1.3.33

Publication

31/10/2025

CVE-2024-37498 Moyenne · 5,3
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Table & Contact Form 7 Database – Tablesome <= 1.0.33 – Unauthenticated Sensitive Information Exposure

The Tablesome – Responsive Table, Woocommerce Automation, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.33 due to insufficient…

Versions affectées

*-1.0.33

Correctif

1.0.34

Publication

04/07/2024

CVE-2024-31388 Moyenne · 4,3
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Table & Contact Form 7 Database – Tablesome <= 1.0.25 – Cross-Site Request Forgery

The Table & Contact Form 7 Database – Tablesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.25. This is due to missing or incorrect nonce validation on the publish_table() function.…

Versions affectées

*-1.0.25

Correctif

1.0.26

Publication

10/04/2024

CVE-2024-29110 Moyenne · 6,1
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Table & Contact Form 7 Database – Tablesome <= 1.0.27 – Reflected Cross-Site Scripting

The Table & Contact Form 7 Database – Tablesome plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.27 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.0.27

Correctif

1.0.28

Publication

16/03/2024

CVE-2023-33999 Moyenne · 6,1
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.0.14

Correctif

1.0.15

Publication

18/07/2023

CVE-2023-1890 Moyenne · 6,1
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Tablesome <= 1.0.8 – Reflected Cross-Site Scripting

The Tablesome plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

[*, 1.0.9)

Correctif

1.0.9

Publication

19/04/2023

CVE-2022-4974 Moyenne · 6,3
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 0.6.7)

Correctif

0.6.7

Publication

04/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités