Cross-Site Request Forgery (CSRF) Vulnerability in Table of Contents Plus
CVE-2024-49250

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 October 2024

What is CVE-2024-49250?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Table of Contents Plus plugin developed by Michael Tran. This security flaw potentially allows attackers to execute unauthorized actions on behalf of authenticated users. Affected users running versions from n/a through 2408 of the Table of Contents Plus plugin are at risk. It is crucial for web administrators to apply necessary updates and mitigate risks associated with this vulnerability to maintain the security integrity of their WordPress sites.

Affected Version(s)

Table of Contents Plus <= 2408

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.