CVE-2025-12845Disclosure

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function in versions 0.5.4 to 1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve plugin table data that can expose email log information. Attackers can leverage this on sites where the table log is enabled in order to trigger a password reset and obtain the reset key.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-19: 1Mentions · 2026-04-11: 1Active Exploitation · 2026-04-11: 1Technical Details · 2026-02-19: 1Technical Details · 2026-04-11: 102-1904-11
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-04-111
Active Exploitation1
Full discourse2 posts
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-12845 Exploit in the wild confirmed for CVE-2025-12845 (CVSS 8.8). The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post announces confirmed active exploitation of CVE-2025-12845 in the wild, noting its CVSS score of 8.8.

    00000333
    5.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2025-12845 pertains to a security flaw in the **Tablesome Table – Contact Form DB** plugin for WordPress, specifically affecting versions **0.5.4 through 1.2.1**. The core issue is a missing capability check within the `get_table_data()` function, which allows authenticated users with Subscriber-level access or higher to retrieve sensitive plugin data, notably email logs. This unauthorized data access can be exploited to escalate privileges and potentially manipulate or misuse sensitive information. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-12845

    Post summary

    The post announces CVE-2025-12845, highlighting a missing capability check in the Tablesome Table – Contact Form DB plugin that permits privileged users to read email logs, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000029
    20 followersView on X

Explore more