A WordPress plugin called “Table & Contact Form 7 Database – Tablesome” has a security vulnerability in versions 1.0.25 and below. This vulnerability, known as Cross-Site Request Forgery, is caused by a lack of proper validation when publishing tables through the “publish_table()” function. This means that someone without proper authorization could publish tables on a website if they can deceive the site administrator into clicking a link.