The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Metrics
Affected Vendors & Products
References
History
Thu, 15 May 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:cminds:cm_table_of_contents:*:*:*:*:*:wordpress:*:* |
Thu, 21 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cminds
Cminds cm Table Of Contents |
|
CPEs | cpe:2.3:a:cminds:cm_table_of_contents:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cminds
Cminds cm Table Of Contents |
|
Metrics |
cvssV3_1
|
Thu, 21 Nov 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
Title | CM Table Of Contents – WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-11-21T06:00:07.135Z
Updated: 2024-11-21T21:48:56.832Z
Reserved: 2024-05-16T19:31:13.629Z
Link: CVE-2024-5029

Updated: 2024-11-21T21:48:49.074Z

Status : Analyzed
Published: 2024-11-21T11:15:35.790
Modified: 2025-05-15T16:12:41.750
Link: CVE-2024-5029

No data.