Vulnerabilities > Toggle THE Title Project

DATE CVE VULNERABILITY TITLE RISK
2019-08-15 CVE-2019-14795 Cross-site Scripting vulnerability in Toggle-The-Title Project Toggle-The-Title 1.4
The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options isAutoSaveValveChecked or isDisableAllPagesValveChecked parameter.
network
low complexity
toggle-the-title-project CWE-79
4.8