PT-2024-19259 · WordPress · Luckywp Table Of Contents

Maksymilian Kubiak

+1

·

Published

2024-06-14

·

Updated

2024-07-03

·

CVE-2024-2218

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions LuckyWP Table of Contents WordPress plugin versions 2.1.4 and earlier
Description The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks. This can occur even when the unfiltered html capability is disallowed, for example, in a multisite setup.
Recommendations For LuckyWP Table of Contents WordPress plugin versions 2.1.4 and earlier, update to a version that addresses the sanitization and escaping of settings to prevent Stored Cross-Site Scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2218

Affected Products

Luckywp Table Of Contents