Tablesome WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability exists in the Tablesome Table WordPress plugin, specifically in the 'Contact Form DB' feature that integrates with WPForms, Contact Form 7, Gravity Forms, Forminator, and Fluent. All versions up to and including 1.1.32 are affected. The issue arises from inadequate file type validation in the 'set_featured_image_from_external_url()' function, allowing unauthenticated users to upload arbitrary files to the server. This could lead to remote code execution, particularly in configurations where unauthenticated users can add featured images and a workflow trigger is active.

Impact

Exploitation of this vulnerability could result in unauthorized file uploads, potentially leading to remote code execution on the affected server.

Remediation

Users are advised to update the Tablesome WordPress plugin to version 1.3.33 or later.

Added: Nov 1, 2025, 7:22 AM
Updated: Nov 1, 2025, 7:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.1
remediation
7.7
relevance
0.9
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.