CVE-2024-6334: Easy Table of Contents < 2.0.67 - Editor+ Stored XSS
The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6334?
CVE-2024-6334 has a medium severity rating due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2024-6334?
To fix CVE-2024-6334, update the Easy Table of Contents WordPress plugin to version 2.0.67.1 or later.
Who is affected by CVE-2024-6334?
High privilege users, such as editors, are primarily affected by CVE-2024-6334 due to improper input sanitization.
What kind of attacks can CVE-2024-6334 enable?
CVE-2024-6334 can enable Cross-Site Scripting (XSS) attacks that exploit unsanitized settings.
Is CVE-2024-6334 exploitable even with unfiltered_html disallowed?
Yes, CVE-2024-6334 is exploitable by high privilege users like editors even when unfiltered_html is disallowed.