4 results (0.010 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks. El complemento Easy Table of Contents de WordPress anterior a 2.0.68 no sanitiza ni escapa a algunos parámetros, lo que podría permitir a usuarios con un rol tan bajo como Editor realizar ataques de Cross-Site Scripting. The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. • https://wpscan.com/vulnerability/8f30e685-00fa-4dbb-b516-2d14e4b13697 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.4EPSS: 0%CPEs: 1EXPL: 1

The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. El complemento Easy Table of Contents de WordPress anterior a 2.0.67.1 no sanitiza ni escapa a algunas de sus configuraciones, lo que podría permitir a usuarios con altos privilegios, como editores, realizar ataques de Cross Site Scripting incluso cuando unfiltered_html no está permitido. The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.0.67 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. • https://wpscan.com/vulnerability/6c09083c-6960-4369-8c5c-ad20e34aaa8b • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 1

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed El complemento Easy Table of Contents de WordPress anterior a 2.0.66 no sanitiza ni escapa a algunas de sus configuraciones, lo que podría permitir a usuarios con altos privilegios, como editores, realizar ataques de Cross-Site Scripting incluso cuando unfiltered_html no está permitido. The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. • https://wpscan.com/vulnerability/3b01044b-355f-40d3-8e11-23a890f98c76 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

The Easy Table of Contents plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the eztoc_reset_options_to_default function in versions up to, and including, 2.0.45.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to reset plugin options. • CWE-862: Missing Authorization •