WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Easy Table Of Contents safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Easy Table Of Contents WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: easy-table-of-contents
  • 600000+ active installs

table of contentstoc

Maintenance status

  • Requires PHP: 5.6.20+

Known vulnerabilities

6 known CVEs on file for Easy Table Of Contents. Reported between 2023 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13738 Easy Table of Contents [easy-table-of-contents] < 2.0.79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.0.79 2.0.79 2026-02-18
CVE-2026-32343 Easy Table of Contents [easy-table-of-contents] < 2.0.81 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.0.81 2.0.81 2026-02-11
CVE-2024-7082 Easy Table of Contents [easy-table-of-contents] < 2.0.68 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.0.68 2.0.68 2024-07-16
CVE-2024-6334 Easy Table of Contents [easy-table-of-contents] < 2.0.67.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.0.67.1 2.0.67.1 2024-06-18
CVE-2024-5573 Easy Table of Contents [easy-table-of-contents] < 2.0.66 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.0.66 2.0.66 2024-06-05
CVE-2023-25469 Easy Table of Contents [easy-table-of-contents] < 2.0.46 Missing Authorization Medium 5.4 < 2.0.46 2.0.46 2023-03-21

CVE-2025-13738

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2026-32343

The Easy Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.80. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2024-7082

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Source: Wordfence

CVE-2024-6334

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Source: Wordfence

CVE-2024-5573

The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Source: Wordfence

CVE-2023-25469

The Easy Table of Contents plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the eztoc_reset_options_to_default function in versions up to, and including, 2.0.45.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to reset plugin options.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.