PT-2026-86356 · Undefined · Undefined

·

CVE-2026-84931

·

Publicado

2026-09-05

·

Atualizado

2026-09-06

CVSS v3.1

6.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
🚨 CVE-2026-84931 The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.
🎖@cveNotify

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-84931

Produtos afetados

Undefined