CVE · Medium

CVE-2024-7082 — Easy Table of Contents [easy-table-of-contents] < 2.0.68

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7082 Easy Table of Contents [easy-table-of-contents] < 2.0.68 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.0.68 2.0.68 2024-07-16

CVE-2024-7082

The Easy Table of Contents plugin for WordPress contains a vulnerability in versions up to 2.0.67.1, allowing an authenticated attacker with editor-level permissions or higher to inject malicious web scripts into pages. These scripts can be executed when a user accesses the affected page, posing a risk to users of multi-site WordPress installations where unfiltered HTML has been disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.