CVE-2024-7082: easy-table-of-contents < 2.0.68 - Editor+ Stored XSS
Published Aug 6, 2024
·Updated
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
Affected Software
2 affected components
Easy Table of Contents Easy Table of Contents<2.0.68
Magazine3 Easy Table Of Contents Wordpress<2.0.68
Event History
Aug 6, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7082?
CVE-2024-7082 is rated as a medium severity vulnerability due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2024-7082?
To fix CVE-2024-7082, update the Easy Table of Contents plugin to version 2.0.68 or later.
3
Who is affected by CVE-2024-7082?
Users of the Easy Table of Contents plugin prior to version 2.0.68 are affected by CVE-2024-7082.
4
What types of attacks can CVE-2024-7082 allow?
CVE-2024-7082 can allow Cross-Site Scripting attacks that exploit unsanitized parameters.
5
What user roles can exploit CVE-2024-7082?
Users with a role as low as Editor can exploit CVE-2024-7082 to perform attacks.