GHSA-w6q9-cjvw-4mhmLowCVSS 3.5

The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its...

Published
September 5, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (1)

📋 Description

The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.

🔗 References (3)