CVE · Medium

CVE-2023-44473 — Table of Contents Plus – Automatic Table of Contents for Posts & Pages [table-of-contents-plus] < 2309 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-44473 Table of Contents Plus – Automatic Table of Contents for Posts & Pages [table-of-contents-plus] < 2309 (closed) Cross-Site Request Forgery (CSRF) Medium 5.4 < 2309 2309 2023-09-29

CVE-2023-44473

The Table of Contents Plus plugin versions prior to 2309 contained a cross-site request forgery vulnerability that could enable attackers to trick authenticated users with elevated privileges into performing unintended actions. Muhammad Daffa identified and disclosed this CSRF flaw, which was subsequently patched in version 2309. Users should upgrade to version 2309 or later to eliminate this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.