CVE-2024-5029

CVE-2024-5029: CM Table Of Contents – WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF

Vendor Unknown
Product CM Table Of Contents
Published November 21, 2024
Last update November 21, 2024

CVSS base score

What the vulnerability does

01Description

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

Key dates

02Disclosure timeline

November 21, 2024 CVE published
November 21, 2024 Record updated