plugin

Table Of Contents Plus Vulnerabilities

12 known security issues reported for the Table Of Contents Plus WordPress plugin. Most recent disclosed Nov 5, 2024.

5 medium

Running Table Of Contents Plus on your site? Check whether your installed version is affected.

Scan your site free

Table of Contents Plus [table-of-contents-plus] < 2411.1

unknown

[en] The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Affected:
up to 2411.1
Fixed in:
2411.1
Disclosed:
Nov 5, 2024

CVE-2024-5578 on NVD →

Table of Contents Plus [table-of-contents-plus] < 2411.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through 2408.

Affected:
up to 2411.1
Fixed in:
2411.1
Disclosed:
Oct 20, 2024

CVE-2024-49250 on NVD →

Table of Contents Plus <= 2411 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2411 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...

CVSS:
5.5
Affected:
up to 2411
Fixed in:
2411.1
Disclosed:
Oct 15, 2024

CVE-2024-5578 on NVD →

Table of Contents Plus <= 2408 - Cross-Site Request Forgery

medium

The Table of Contents Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2408. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...

CVSS:
4.3
Affected:
up to 2408
Fixed in:
2411
Disclosed:
Oct 14, 2024

CVE-2024-49250 on NVD →

Table of Contents Plus [table-of-contents-plus] < 2309

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus plugin <= 2302 versions.

Affected:
up to 2309
Fixed in:
2309
Disclosed:
Oct 9, 2023

CVE-2023-44473 on NVD →

Table of Contents Plus <= 2302 - Cross-Site Request Forgery

medium

The Table of Contents Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2302. This is due to incorrect nonce validation on the save_admin_options() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request gr...

CVSS:
4.3
Affected:
up to 2302
Fixed in:
2309
Disclosed:
Sep 29, 2023

CVE-2023-44473 on NVD →

Table of Contents Plus [table-of-contents-plus] < 2309

unknown

Update the WordPress Table of Contents Plus plugin to the latest available version (at least 2309). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Table of Contents Plus Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements,...

Affected:
up to 2309
Fixed in:
2309
Disclosed:
Sep 20, 2023

Table of Contents Plus <= 2302 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2302 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 2309
Fixed in:
2309
Disclosed:
Sep 19, 2023

Table of Contents Plus [table-of-contents-plus] < 2309

unknown

The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2302 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

Affected:
up to 2309
Fixed in:
2309
Disclosed:
Sep 19, 2023

Table of Contents Plus [table-of-contents-plus] < 2212

unknown

[en] The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users su...

Affected:
up to 2212
Fixed in:
2212
Disclosed:
Jan 9, 2023

CVE-2022-4479 on NVD →

Table of Contents Plus <= 2106 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'label' properties in the [toc] and [sitemap_pages] shortcodes respectively in versions up to, and including, 2106 due to insufficient input sanitization and output escaping. This makes it possible for authe...

CVSS:
5.5
Affected:
up to 2106
Fixed in:
2212
Disclosed:
Dec 16, 2022

CVE-2022-4479 on NVD →

Table of Contents Plus [table-of-contents-plus] < 2309

unknown

The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2302 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

Affected:
up to 2309
Fixed in:
2309

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database