CVE-2026-66659

WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.


We have discovered 1,474 live websites that are affected by CVE-2026-66659.

Run a Free Instant Scan




Affected Software

Product  Tablesome
Category Wordpress Plugins
Vulnerable Domains1,474 live websites (100% of Tablesome install base)
Vulnerable Versions
  • from 0 through 1.2.9
Vulnerable Versions Count74 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Nguyen Ba Khanh - HPT Vietnam Corporation | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66659
United States420 websites



Germany139 websites
India83 websites
GB77 websites
France57 websites
Netherlands48 websites
Italy47 websites
Canada36 websites
Brazil32 websites
South Africa32 websites

Website Distribution by TLD

Number of websites using CVE-2026-66659
.com511 websites
.org177 websites
.de76 websites
.nl42 websites
.co.uk36 websites
.it35 websites
.com.br31 websites
.net30 websites
.ch27 websites
.fr25 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66659

Top websites that are affected by CVE-2026-66659. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States*,***
*********.com United States**,***
****.com United States**,***
*********.***.ua Ukraine**,***
*************.com United States**,***
**********.at Austria***,***
******.com United States***,***
***********.com United States***,***
***********.com United States***,***
*********.org United States***,***
See full domain list

FAQ

CVE-2026-66659 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Tablesome
A total of 1,474 websites have been identified as vulnerable to CVE-2026-66659, based on global website indexing conducted by WebTechSurvey.
The Tablesome is affected by the CVE-2026-66659 vulnerability.
Tablesome versions up to and including 1.2.9 are vulnerable to CVE-2026-66659.