Theluckywp
theluckywp
6 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Theluckywp 1Luckywp Table Of Contents May 15, 2025 Apr 3, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due to missing or incorrect nonce validation on the 'ajaxEdit' function...Show more |
1Theluckywp 1Luckywp Table Of Contents May 7, 2025 Dec 12, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when...Show more |
1Theluckywp 1Luckywp Table Of Contents May 13, 2025 Jun 14, 2024 N/A· v4 4.6 MEDIUM· v3 N/A· v2 The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even whe...Show more |
1Theluckywp 1Luckywp Table Of Contents Apr 8, 2026 May 22, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping....Show more |
1Theluckywp 1Luckywp Table Of Contents Apr 8, 2026 May 22, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output esc...Show more |
1Theluckywp 1Luckywp Table Of Contents Apr 8, 2026 May 22, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output esc...Show more |