Resources /
WordPress Plugins /
Easy Table Of Contents
PLUGIN SECURITY
Is Easy Table Of Contents safe?
Known vulnerabilities, PHP compatibility and safer alternatives for the Easy Table Of Contents WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
- Slug:
easy-table-of-contents
- 600000+ active installs
table of contentstoc
Maintenance status
Known vulnerabilities
6 known CVEs on file for Easy Table Of Contents.
Reported between 2023 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13738
|
Easy Table of Contents [easy-table-of-contents] < 2.0.79 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 2.0.79
|
2.0.79 |
2026-02-18 |
—
|
|
CVE-2026-32343
|
Easy Table of Contents [easy-table-of-contents] < 2.0.81 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 2.0.81
|
2.0.81 |
2026-02-11 |
—
|
|
CVE-2024-7082
|
Easy Table of Contents [easy-table-of-contents] < 2.0.68 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.0.68
|
2.0.68 |
2024-07-16 |
—
|
|
CVE-2024-6334
|
Easy Table of Contents [easy-table-of-contents] < 2.0.67.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.0.67.1
|
2.0.67.1 |
2024-06-18 |
—
|
|
CVE-2024-5573
|
Easy Table of Contents [easy-table-of-contents] < 2.0.66 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.9
|
< 2.0.66
|
2.0.66 |
2024-06-05 |
—
|
|
CVE-2023-25469
|
Easy Table of Contents [easy-table-of-contents] < 2.0.46 |
Missing Authorization |
Medium
5.4
|
< 2.0.46
|
2.0.46 |
2023-03-21 |
—
|
CVE-2025-13738
The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2026-32343
The Easy Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.80. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2024-7082
The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Source:
Wordfence
CVE-2024-6334
The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Source:
Wordfence
CVE-2024-5573
The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Source:
Wordfence
CVE-2023-25469
The Easy Table of Contents plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the eztoc_reset_options_to_default function in versions up to, and including, 2.0.45.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to reset plugin options.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.