THREAT OPS › Threat News › [NVD] CVE-2026-84931 (MEDIUM 6.8) — The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute
[NVD] CVE-2026-84931 (MEDIUM 6.8) — The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute
CVE-2026-84931 CVSS: 6.8 MEDIUM Published: 2026-09-05T07:17:14.600
The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, inclu
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-84931cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84931