CVE-2026-66645: WordPress Table Of Contents Block plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
Affected Software
1 affected component
WordPress Table of Contents Block<=1.5.0
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which sites and users are in scope?
Sites using Table Of Contents Block version 1.5.0 or earlier are affected. Exploitation requires an authenticated WordPress account with Contributor-level access.
2
What does an attacker need to exploit this?
An attacker must be able to authenticate as a Contributor and induce a user to interact with the malicious content. The vulnerability is network-accessible and has low attack complexity.
3
What should be done if the plugin cannot be updated immediately?
Update the Table Of Contents Block plugin to a version later than 1.5.0 when available. Until then, restrict or remove Contributor access for untrusted users and review Contributor-created content for suspicious script payloads.