Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator table-of-contents-creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through <= 1.6.4.1.
Published: 2026-03-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (Reflected XSS)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input During Web Page Generation that allows Reflected Cross‑Site Scripting (XSS) in the Markbeljaars Table of Contents Creator plugin. When the plugin receives user‑supplied data through certain request parameters, it fails to escape the input before rendering the page, causing malicious script to be reflected back to the browser. The weakness is identified as CWE‑79 and can enable an attacker to inject and execute arbitrary JavaScript in the context of a victim’s browser session.

Affected Systems

All installations of Markbeljaars Table of Contents Creator up to and including version 1.6.4.1 are affected. The supplier’s product list confirms Markbeljaars:Table of Contents Creator, and the description states "from n/a through 1.6.4.1." Accordingly, any WordPress site running this plugin at or below that version is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates medium‑to‑high severity. EPSS data is not available and the flaw is not listed in KEV, suggesting limited known exploitation. The likely attack vector involves a crafted URL that includes malicious input; a user who visits the URL will have the script executed in their browser. This requires user interaction but can be leveraged through social engineering or phishing to deliver the payload. Prompt patching is recommended due to the medium‑to‑high risk level.

Generated by OpenCVE AI on March 19, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Table of Contents Creator plugin to a version newer than 1.6.4.1 (or apply the vendor patch if available).
  • If an upgrade cannot be performed immediately, disable or uninstall the plugin to eliminate the vulnerability.
  • Monitor the vendor’s website or security advisories for new patches or updates.

Generated by OpenCVE AI on March 19, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:45:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through 1.6.4.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator table-of-contents-creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through <= 1.6.4.1.
References

Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Markbeljaars
Markbeljaars table Of Contents Creator
Wordpress
Wordpress wordpress
Vendors & Products Markbeljaars
Markbeljaars table Of Contents Creator
Wordpress
Wordpress wordpress

Thu, 19 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through 1.6.4.1.
Title WordPress Table of Contents Creator plugin <= 1.6.4.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Markbeljaars Table Of Contents Creator
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-23T14:13:58.213Z

Reserved: 2025-12-24T13:59:58.565Z

Link: CVE-2025-68836

cve-icon Vulnrichment

Updated: 2026-03-19T13:31:22.526Z

cve-icon NVD

Status : Deferred

Published: 2026-03-19T09:16:16.767

Modified: 2026-04-23T15:36:09.043

Link: CVE-2025-68836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T14:15:23Z

Weaknesses