Cross-Site Request Forgery Vulnerability in Magazine3's Easy Table of Contents Plugin
CVE-2026-32343

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 March 2026

What is CVE-2026-32343?

The Magazine3 Easy Table of Contents plugin has a vulnerability that allows attackers to exploit Cross-Site Request Forgery (CSRF). This security flaw enables unauthorized commands to be transmitted from a user that the web application trusts. It affects versions of the Easy Table of Contents plugin prior to and including 2.0.80. This vulnerability could potentially lead to malicious actions being performed on behalf of an unsuspecting user, compromising the security of WordPress sites that utilize this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Easy Table of Contents 0 <= 2.0.80

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Montoya | Patchstack Bug Bounty Program
.