THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-15694 — The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltere

[NVD] CVE-2025-15694 — The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltere

mednvdPublished 2026-09-05

CVE-2025-15694 CVSS: None Published: 2026-09-05T07:17:10.447

The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-15694