Description
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Contributor Cross Site Scripting (XSS) has been identified in the Table Of Contents Block plugin up to version 1.5.0. The flaw allows an attacker who can submit or edit content in the block to inject arbitrary JavaScript into the rendered page. If executed, the injected script runs in the browsers of all users who view the affected page, potentially leading to credential theft, session hijacking, or site defacement.

Affected Systems

WPDeveloper’s Table Of Contents Block plugin, versions 1.5.0 and earlier.

Risk and Exploitability

With a CVSS score of 6.5 and no EPSS data available, the vulnerability is considered of moderate severity. The flaw is exploitable by users with contributor or higher privileges who can insert or modify block content, indicating that privileged access is required. Because the attack is limited to users able to edit plugin content, the threat surface is narrower than an unauthenticated vulnerability, yet the potential impact on site visitors remains significant. The vulnerability is not currently listed in the CISA KEV catalog, but organizations should treat it with equal caution as other moderate‑severity XSS flaws.

Generated by OpenCVE AI on August 18, 2026 at 17:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPDeveloper Table Of Contents Block to the latest release (version 1.5.1 or newer) to eliminate the XSS flaw.
  • If an upgrade is not immediately possible, restrict the ability to edit or add block content to trusted users only, or remove custom HTML from contributor capability.
  • Review existing published content in the block for injected script and remove any suspicious code.
  • Implement content security policy (CSP) headers to mitigate the impact of potential injection as a secondary defense.

Generated by OpenCVE AI on August 18, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdeveloper
Wpdeveloper table Of Contents Block
Vendors & Products Wordpress
Wordpress wordpress
Wpdeveloper
Wpdeveloper table Of Contents Block

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
Title WordPress Table Of Contents Block plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpdeveloper Table Of Contents Block
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:27:51.121Z

Reserved: 2026-07-27T14:00:38.499Z

Link: CVE-2026-66645

cve-icon Vulnrichment

Updated: 2026-08-18T14:27:47.591Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:16:59.300

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-66645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:34Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')