• Resolved victormontes

    (@victormontes)


    It has a critical vulnerability, according to Wordfence.

    The Table Of Contents Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.5.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support Mahbub Shovan

    (@mahbubshovan)

    Hi @victormontes

    I hope you are doing well. Thank you for reporting this and sharing the Wordfence link. We have reviewed the issue and confirmed that it is not a critical or remotely exploitable vulnerability. It requires an authenticated user with Contributor-level access or higher to exploit.

    We have confirmed the issue and a fix is already in development. We will release the update after completing our testing.

    For now, no action is required if all users with Contributor access are trusted. Please keep auto-updates enabled to receive the fix once released.

    We’ll let you know when the update is live.

    Thanks

    Plugin Support Mahbub Shovan

    (@mahbubshovan)

    Hi @victormontes

    I hope you are doing well. We’re aware of the reported vulnerability affecting the Table Of Contents Block plugin. The issue has already been addressed, and we have released an updated version containing the required security fix.

    We recommend updating the plugin to the latest available version from the WordPress.org repository to ensure your site is protected.

    Please feel free to reach out if you have any further concerns or need assistance with the update.

    Have a nice day.

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.