CM Table Of Contents – Clear navigation for better content discovery [cm-table-of-content] < 1.2.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Mar 3, 2025
CVE-2025-24758 on NVD →
CM Table Of Contents – Clear navigation for better content discovery [cm-table-of-content] < 1.2.4
unknown
[en] The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Nov 21, 2024
CVE-2024-5029 on NVD →
CM Table Of Contents – Clear navigation for better content discovery [cm-table-of-content] < 1.2.3
unknown
[en] The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Nov 18, 2024
CVE-2024-5030 on NVD →
CM Table Of Contents <= 1.2.3 - Cross-Site Request Forgery
medium
The CM Table Of Contents – WordPress TOC Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to inject malicious web scripts...
- CVSS:
- 4.3
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Oct 31, 2024
CVE-2024-5029 on NVD →
CM Table Of Contents <= 1.2.2 - Cross-Site Request Forgery
medium
The CM Table Of Contents – WordPress TOC Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to reset plugin settings via a...
- CVSS:
- 4.3
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- Oct 28, 2024
CVE-2024-5030 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database