Table of Contents Plus [table-of-contents-plus] < 2411.1
unknown
[en] The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 2411.1
- Fixed in:
- 2411.1
- Disclosed:
- Nov 5, 2024
CVE-2024-5578 on NVD →
Table of Contents Plus [table-of-contents-plus] < 2411.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through 2408.
- Affected:
- up to 2411.1
- Fixed in:
- 2411.1
- Disclosed:
- Oct 20, 2024
CVE-2024-49250 on NVD →
Table of Contents Plus <= 2411 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2411 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...
- CVSS:
- 5.5
- Affected:
- up to 2411
- Fixed in:
- 2411.1
- Disclosed:
- Oct 15, 2024
CVE-2024-5578 on NVD →
Table of Contents Plus <= 2408 - Cross-Site Request Forgery
medium
The Table of Contents Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2408. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 2408
- Fixed in:
- 2411
- Disclosed:
- Oct 14, 2024
CVE-2024-49250 on NVD →
Table of Contents Plus [table-of-contents-plus] < 2309
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus plugin <= 2302 versions.
- Affected:
- up to 2309
- Fixed in:
- 2309
- Disclosed:
- Oct 9, 2023
CVE-2023-44473 on NVD →
Table of Contents Plus <= 2302 - Cross-Site Request Forgery
medium
The Table of Contents Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2302. This is due to incorrect nonce validation on the save_admin_options() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 2302
- Fixed in:
- 2309
- Disclosed:
- Sep 29, 2023
CVE-2023-44473 on NVD →
Table of Contents Plus [table-of-contents-plus] < 2309
unknown
Update the WordPress Table of Contents Plus plugin to the latest available version (at least 2309).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Table of Contents Plus Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements,...
- Affected:
- up to 2309
- Fixed in:
- 2309
- Disclosed:
- Sep 20, 2023
Table of Contents Plus <= 2302 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2302 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 2309
- Fixed in:
- 2309
- Disclosed:
- Sep 19, 2023
Table of Contents Plus [table-of-contents-plus] < 2309
unknown
The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2302 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- Affected:
- up to 2309
- Fixed in:
- 2309
- Disclosed:
- Sep 19, 2023
Table of Contents Plus [table-of-contents-plus] < 2212
unknown
[en] The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users su...
- Affected:
- up to 2212
- Fixed in:
- 2212
- Disclosed:
- Jan 9, 2023
CVE-2022-4479 on NVD →
Table of Contents Plus <= 2106 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'label' properties in the [toc] and [sitemap_pages] shortcodes respectively in versions up to, and including, 2106 due to insufficient input sanitization and output escaping. This makes it possible for authe...
- CVSS:
- 5.5
- Affected:
- up to 2106
- Fixed in:
- 2212
- Disclosed:
- Dec 16, 2022
CVE-2022-4479 on NVD →
Table of Contents Plus [table-of-contents-plus] < 2309
unknown
The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2302 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- Affected:
- up to 2309
- Fixed in:
- 2309
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database