HTML Injection Vulnerability in Joli Table Of Contents Plugin for WordPress
CVE-2026-84931

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-84931?

The Joli Table Of Contents plugin for WordPress, prior to version 3.0.3, fails to properly sanitize or escape shortcode attribute values. This vulnerability allows users with author privileges or higher to inject arbitrary HTML attributes and JavaScript into posts. As a result, code executed in the browser of any visitor—regardless of their user role—can compromise the site's security, even on multisite installations where such users typically cannot post unfiltered HTML content. This could lead to serious security breaches, including data theft and unauthorized access.

Affected Version(s)

Joli Table Of Contents 0 < 3.0.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Artus KG
WPScan
.