Impact
The Joli Table Of Contents WordPress plugin contains a stored cross‑site scripting flaw that occurs when certain configuration values are rendered in an administrative page without proper escaping or sanitisation. Because the values are persisted and displayed to users who have administrative or higher privileges, an attacker who can access an administrator account can inject arbitrary HTML or JavaScript. The resulting client‑side code can execute in the context of the logged‑in administrator, allowing session hijacking, credential theft, defacement, or further attacks within the trusted environment. This vulnerability is classified as CWE‑79.
Affected Systems
The vulnerability affects all WordPress sites that have installed the Joli Table Of Contents plugin with a version earlier than 2.8.1, specifically the 2.0.0 through 2.8.0 releases. The plugin is developed by the vendor 'Unknown', and the flaw resides in the admin UI that displays plugin settings. Systems running WordPress on single‑site or multisite installations, especially those that allow non‑trusted administrators, are at risk until the plugin is updated to a fixed release.
Risk and Exploitability
The flaw is only exploitable by users with administrative or higher privileges; it does not provide arbitrary code execution on the server. No CVSS score is available, and EPSS data is not provided, but the lack of a server‑side impact limits the attack surface to client‑side scripts. The KEV catalog does not list this vulnerability, suggesting no known widespread exploitation yet. Nonetheless, the potential for attackers to perform session hijacking or defacement within the privileged administrative context warrants prompt remediation. In multisite or shared environments, a compromised administrator could spread malicious payloads across multiple subsites, amplifying the risk.
OpenCVE Enrichment