THREAT OPS › Threat News › [NVD] CVE-2025-15694 — The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltere
[NVD] CVE-2025-15694 — The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltere
CVE-2025-15694 CVSS: None Published: 2026-09-05T07:17:10.447
The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisi
Indicators of compromise
- CVE-2025-15694cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-15694