Impact
A stored cross‑site scripting flaw exists in the KaizenCoders Table of Content plugin for WordPress versions up to 1.5.3.1. The plugin fails to neutralize user‑supplied input before rendering it on a page, allowing an attacker to inject arbitrary JavaScript that is then executed in the browsers of users who view the affected content. This vulnerability primarily threatens confidentiality and integrity by enabling attackers to steal session cookies, deface sites, or launch phishing attacks that appear legitimate to visitors.
Affected Systems
The affected system is WordPress sites that have installed the KaizenCoders Table of Content plugin – any release numbered 1.5.3.1 or earlier.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high risk, while the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated user submitting malicious content through the plugin’s content‑creation interface; the input persists and is rendered to other users, resulting in site compromise if victim browsers execute the injected scripts. No additional exploitation prerequisites beyond the plugin’s input mechanism are indicated in the description.
OpenCVE Enrichment
EUVD