Impact
The flaw is an Improper Neutralization of Input During Web Page Generation that permits Reflected XSS in the Markbeljaars Table of Contents Creator plugin. Based on the description, it is inferred that the plugin accepts user‑supplied input via request parameters and outputs it without proper escaping, causing malicious scripts to be reflected back to the browser. This weakness, classified as CWE‑79, allows an attacker to run arbitrary JavaScript in a victim’s browser context when the vulnerable page is accessed.
Affected Systems
All installations of Markbeljaars Table of Contents Creator up to and including version 1.6.4.1 are affected. The supplier’s product list confirms Markbeljaars:Table of Contents Creator, and the description states "from n/a through 1.6.4.1." Accordingly, any WordPress site running this plugin at or below that version is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates medium‑to‑high severity. EPSS score is less than 1% (approximately 0.04%) and the flaw is not listed in KEV, suggesting limited known exploitation. The likely attack vector involves a crafted URL that includes malicious input; a user who visits the URL will have the script executed in their browser. This requires user interaction but can be leveraged through social engineering or phishing to deliver the payload. Prompt patching is recommended due to the medium‑to‑high risk level.
OpenCVE Enrichment