Vulnerabilities > Theluckywp > Luckywp Table OF Contents > 2.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-04-03 | CVE-2025-2299 | Cross-site Scripting vulnerability in Theluckywp Luckywp Table of Contents The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. | 6.1 |
2024-05-22 | CVE-2023-6487 | Cross-site Scripting vulnerability in Theluckywp Luckywp Table of Contents The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-05-22 | CVE-2024-2119 | Cross-site Scripting vulnerability in Theluckywp Luckywp Table of Contents The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. | 6.1 |
2024-05-22 | CVE-2024-2953 | Cross-site Scripting vulnerability in Theluckywp Luckywp Table of Contents The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. | 4.8 |