HTML Injection Vulnerability in Joli Table Of Contents Plugin for WordPress
CVE-2026-84931
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 5 September 2026
Badges
What is CVE-2026-84931?
The Joli Table Of Contents plugin for WordPress, prior to version 3.0.3, fails to properly sanitize or escape shortcode attribute values. This vulnerability allows users with author privileges or higher to inject arbitrary HTML attributes and JavaScript into posts. As a result, code executed in the browser of any visitor—regardless of their user role—can compromise the site's security, even on multisite installations where such users typically cannot post unfiltered HTML content. This could lead to serious security breaches, including data theft and unauthorized access.
Affected Version(s)
Joli Table Of Contents 0 < 3.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.