The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
History

Wed, 06 Nov 2024 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CPEs cpe:2.3:a:dublue:table_of_contents_plus:*:*:*:*:*:wordpress:*:*

Tue, 05 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Dublue
Dublue table Of Contents Plus
CPEs cpe:2.3:a:dublue:table_of_contents_plus:-:*:*:*:*:wordpress:*:*
Vendors & Products Dublue
Dublue table Of Contents Plus
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 Nov 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Title Table of Contents Plus <= 2408 - Editor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-11-05T06:00:06.744Z

Updated: 2024-11-05T16:21:20.702Z

Reserved: 2024-05-31T19:58:11.335Z

Link: CVE-2024-5578

cve-icon Vulnrichment

Updated: 2024-11-05T16:21:15.626Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-05T06:15:05.760

Modified: 2024-11-06T15:44:19.040

Link: CVE-2024-5578

cve-icon Redhat

No data.