CVE-2025-60244: WordPress TableOn plugin <= 1.0.5.1 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RealMag777 TableOn posts-table-filterable allows Code Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60244?
CVE-2025-60244 is classified as a medium severity vulnerability due to its potential for code injection via improper neutralization of HTML tags.
How do I fix CVE-2025-60244?
To fix CVE-2025-60244, upgrade the RealMag777 TableOn plugin to a version newer than 1.0.4.2.
What versions of RealMag777 TableOn are affected by CVE-2025-60244?
CVE-2025-60244 affects RealMag777 TableOn versions from its initial release up to and including version 1.0.4.2.
Is CVE-2025-60244 a cross-site scripting (XSS) vulnerability?
Yes, CVE-2025-60244 is a basic cross-site scripting (XSS) vulnerability that allows code injection through improperly handled HTML tags.
What are the potential impacts of CVE-2025-60244?
The potential impacts of CVE-2025-60244 include unauthorized code execution in the context of the affected web application, leading to information theft or site defacement.