Impact
Contributor Cross Site Scripting (XSS) has been identified in the Table Of Contents Block plugin up to version 1.5.0. The flaw allows an attacker who can submit or edit content in the block to inject arbitrary JavaScript into the rendered page. If executed, the injected script runs in the browsers of all users who view the affected page, potentially leading to credential theft, session hijacking, or site defacement.
Affected Systems
WPDeveloper’s Table Of Contents Block plugin, versions 1.5.0 and earlier.
Risk and Exploitability
With a CVSS score of 6.5 and no EPSS data available, the vulnerability is considered of moderate severity. The flaw is exploitable by users with contributor or higher privileges who can insert or modify block content, indicating that privileged access is required. Because the attack is limited to users able to edit plugin content, the threat surface is narrower than an unauthenticated vulnerability, yet the potential impact on site visitors remains significant. The vulnerability is not currently listed in the CISA KEV catalog, but organizations should treat it with equal caution as other moderate‑severity XSS flaws.
OpenCVE Enrichment