plugin

Easy Table Of Contents Vulnerabilities

6 known security issues reported for the Easy Table Of Contents WordPress plugin. Most recent disclosed Feb 18, 2026.

6 medium

Running Easy Table Of Contents on your site? Check whether your installed version is affected.

Scan your site free

Easy Table of Contents <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...

CVSS:
6.4
Affected:
up to 2.0.78
Fixed in:
2.0.79
Disclosed:
Feb 18, 2026

CVE-2025-13738 on NVD →

Easy Table of Contents <= 2.0.80 - Cross-Site Request Forgery

medium

The Easy Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.80. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted th...

CVSS:
4.3
Affected:
up to 2.0.80
Fixed in:
2.0.81
Disclosed:
Feb 11, 2026

CVE-2026-32343 on NVD →

Easy Table of Contents <= 2.0.67.1 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbi...

CVSS:
4.4
Affected:
up to 2.0.67.1
Fixed in:
2.0.68
Disclosed:
Jul 16, 2024

CVE-2024-7082 on NVD →

Easy Table of Contents <= 2.0.67 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitr...

CVSS:
4.4
Affected:
up to 2.0.67
Fixed in:
2.0.67.1
Disclosed:
Jun 18, 2024

CVE-2024-6334 on NVD →

Easy Table of Contents <= 2.0.65 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
4.4
Affected:
up to 2.0.65
Fixed in:
2.0.66
Disclosed:
Jun 5, 2024

CVE-2024-5573 on NVD →

Easy Table of Contents <= 2.0.45.2 - Missing Authorization via eztoc_reset_options_to_default

medium

The Easy Table of Contents plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the eztoc_reset_options_to_default function in versions up to, and including, 2.0.45.2. This makes it possible for authenticated attackers, with subscriber-level acces...

CVSS:
5.4
Affected:
up to 2.0.45.2
Fixed in:
2.0.46
Disclosed:
Mar 21, 2023

CVE-2023-25469 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database