CVE-2024-5030

CVE-2024-5030: CM Table Of Contents – WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF

Vendor Unknown
Product CM Table Of Contents
Published November 18, 2024
Last update November 18, 2024

CVSS base score

What the vulnerability does

01Description

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

Key dates

02Disclosure timeline

November 18, 2024 CVE published
November 18, 2024 Record updated