CVE-2025-12845

HIGH EXPLOITED

Tablesome Table 0.5.4-1.2.1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-12845 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function in versions 0.5.4 to 1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve plugin table data that can expose email log information. Attackers can leverage this on sites where the table log is enabled in order to trigger a password reset and obtain the reset key.

Scores

CVSS v3 8.8
EPSS 0.0036
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-02-19
CWE
CWE-862
Status published
Published Feb 19, 2026
Tracked Since Feb 19, 2026