Impact
The Joli Table Of Contents WordPress plugin before version 3.0.3 does not sanitise or escape a value supplied to a shortcode attribute before outputting it inside an HTML element’s attribute, allowing users with the Author role or higher to embed arbitrary attributes and JavaScript. When other users, even those with elevated privileges, view the post, the injected script runs in their browser, effectively allowing the author to execute code within the context of any viewer’s session.
Affected Systems
WordPress sites that have the Joli Table Of Contents plugin installed on any version earlier than 3.0.3, including all single‑site and multisite deployments where the shortcode is enabled.
Risk and Exploitability
The vulnerability presents a high‑risk stored XSS vector requiring only author‑level access and the ability to edit a post containing the shortcode. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalogue. Attackers can inject malicious code that will execute in the browsers of all users who view the affected post, including administrators.
OpenCVE Enrichment