CVE · Medium

CVE-2024-6334 — Easy Table of Contents [easy-table-of-contents] < 2.0.67.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6334 Easy Table of Contents [easy-table-of-contents] < 2.0.67.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.0.67.1 2.0.67.1 2024-06-18

CVE-2024-6334

The Easy Table of Contents plugin for WordPress contains a security flaw that allows attackers with editor-level permissions or higher to inject malicious code into pages. This code will execute when a user views the affected page, posing a risk to WordPress sites that use the plugin, particularly those with multi-site installations or where unfiltered HTML is disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.