CVE-2026-3513: TableOn – WordPress Posts Table Filterable <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableonbutton' shortcode in all versions up to and including 1.0.4.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'class', 'helplink', 'popuptitle', and 'helptitle'. The doshortcodebutton() function extracts these attributes without sanitization and passes them to TABLEONHELPER::drawhtmlitem(), which concatenates attribute values into HTML using single quotes without escaping (line 29: $item .= " {$key}='{$value}'"). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3513?
The severity of CVE-2026-3513 is medium with a CVSS score of 6.4.
How do I fix CVE-2026-3513?
To fix CVE-2026-3513, update the TableOn – WordPress Posts Table Filterable plugin to the latest version beyond 1.0.4.4.
What type of vulnerability is CVE-2026-3513?
CVE-2026-3513 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-3513?
Users with an authenticated role of Contributor and above using versions up to and including 1.0.4.4 are affected by CVE-2026-3513.
How is CVE-2026-3513 exploited?
CVE-2026-3513 can be exploited through insufficient input sanitization and output escaping of user-supplied shortcode attributes.