Impact
The Rich Table of Contents plugin contains a missing authorization flaw that permits users to invoke functionality that should be restricted. The vulnerability can allow an attacker to perform actions, such as viewing or modifying plugin settings or content, that exceed the user's intended permissions.
Affected Systems
Affects Croover.inc Rich Table of Contents plugin versions up to and including 1.4.0. Users running any version from the initial release through 1.4.0 are impacted.
Risk and Exploitability
With a CVSS score of 4.3 and an EPSS score below 1%, the overall risk is moderate, and the likelihood of exploitation is low. The issue is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation. The attack vector is inferred to be remote via the WordPress web interface, requiring access to the plugin’s administrative endpoints; an authenticated or compromised user account would likely need to exploit the flaw.
OpenCVE Enrichment
EUVD