WordPress Plugin Vulnerabilities

Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS

Description

The plugin does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Krugov Artyom
Submitter
Krugov Aryom
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 1 day ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other