CVE · Medium

CVE-2023-25469 — Easy Table of Contents [easy-table-of-contents] < 2.0.46

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-25469 Easy Table of Contents [easy-table-of-contents] < 2.0.46 Missing Authorization Medium 5.4 < 2.0.46 2.0.46 2023-03-21

CVE-2023-25469

The Easy Table of Contents plugin for WordPress contains a vulnerability in versions 2.0.45.2 and earlier where the eztoc_reset_options_to_default function lacks proper permission validation. This flaw allows any authenticated user with subscriber or higher privileges to reset the plugin's options without authorization, potentially resulting in data loss and unwanted configuration changes.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.