
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Security & Risk Analysis
wordpress.org/plugins/tablesomePowerful Table, Form & Mail Automations. Form Entry Management (+ frontend table ), integrate with MailChimp, G Sheets, CF7, WPForms, Elementor, etc.
Is Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Safe to Use in 2026?
High Risk
Score 37/100Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent carries significant security risk with 11 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
Tablesome v1.2.6 presents a mixed security posture. While the code demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, several significant concerns remain. The static analysis reveals a notable attack surface with 7 AJAX handlers, 4 of which lack authentication checks. This is a critical oversight that could allow unauthorized actions. The taint analysis is clean, which is positive, but it only analyzed a single flow, suggesting this might not be a comprehensive assessment of potential vulnerabilities.
Key Concerns
- 4 unprotected AJAX handlers
- 2 currently unpatched CVEs
- 1 critical, 1 high historical CVE
- History of diverse vulnerability types
- Bundled Freemius library
- Large number of SQL queries
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.2.3 - Authenticated (Subscriber+) SQL Injection
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent 0.5.4 - 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure and Privilege Escalation
Tablesome <= 1.2.2 - Missing Authorization
Tablesome <= 1.1.35.1 - Authenticated (Subscriber+) Information Exposure
Tablesome <= 1.1.35.1 - Missing Authorization
Tablesome <= 1.1.34 - Missing Authorization
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 - Unauthenticated Arbitrary File Upload
Table & Contact Form 7 Database – Tablesome <= 1.0.33 - Unauthenticated Sensitive Information Exposure
Table & Contact Form 7 Database – Tablesome <= 1.0.25 - Cross-Site Request Forgery
Table & Contact Form 7 Database – Tablesome <= 1.0.27 - Reflected Cross-Site Scripting
Tablesome <= 1.0.8 - Reflected Cross-Site Scripting
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Attack Surface
AJAX Handlers 7
Shortcodes 2
WordPress Hooks 74
Maintenance & Trust
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Maintenance & Trust
Maintenance Signals
Community Trust
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Alternatives
Integration for Airtable – WPForms, Gravity Forms, CF7, Ninja Forms & More
integration-for-airtable
Send WordPress form submissions to Airtable automatically. Map form fields to Airtable columns — no Zapier, no Make, no third-party automation needed.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Successful Redirection for Contact Form
cf7-redirection
A simple add-on for Forms that adds a redirect option after form sent successfully.
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Developer Profile
2 plugins · 17K total installs
How We Detect Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tablesome/assets/css/admin.css/wp-content/plugins/tablesome/assets/css/style.css/wp-content/plugins/tablesome/assets/css/frontend.css/wp-content/plugins/tablesome/assets/css/vendor/dataTables.bootstrap.min.css/wp-content/plugins/tablesome/assets/js/admin.js/wp-content/plugins/tablesome/assets/js/frontend.js/wp-content/plugins/tablesome/assets/js/vendor/jquery.dataTables.min.js/wp-content/plugins/tablesome/assets/js/vendor/dataTables.bootstrap.min.js+3 more/wp-content/plugins/tablesome/assets/js/admin.js/wp-content/plugins/tablesome/assets/js/frontend.js/wp-content/plugins/tablesome/assets/js/vendor/jquery.dataTables.min.js/wp-content/plugins/tablesome/assets/js/vendor/dataTables.bootstrap.min.js/wp-content/plugins/tablesome/assets/js/vendor/moment.min.js/wp-content/plugins/tablesome/assets/js/vendor/datetime-moment.js+1 more/wp-content/plugins/tablesome/assets/css/admin.css?ver=/wp-content/plugins/tablesome/assets/css/style.css?ver=/wp-content/plugins/tablesome/assets/css/frontend.css?ver=/wp-content/plugins/tablesome/assets/css/vendor/dataTables.bootstrap.min.css?ver=/wp-content/plugins/tablesome/assets/js/admin.js?ver=/wp-content/plugins/tablesome/assets/js/frontend.js?ver=/wp-content/plugins/tablesome/assets/js/vendor/jquery.dataTables.min.js?ver=/wp-content/plugins/tablesome/assets/js/vendor/dataTables.bootstrap.min.js?ver=/wp-content/plugins/tablesome/assets/js/vendor/moment.min.js?ver=/wp-content/plugins/tablesome/assets/js/vendor/datetime-moment.js?ver=/wp-content/plugins/tablesome/assets/js/vendor/tablesome-form-submit.js?ver=HTML / DOM Fingerprints
tablesome-data-tabletablesome-table-wrappertablesome-backend-list-tabletablesome-frontend-list-table<!-- Tablesome data table --><!-- Tablesome table --><!-- tablesome-table -->data-tablesome-table-iddata-tablesome-table-row-idtablesome_paramstablesome_form_submit_config[tablesome[tablesome_form_entries