What is CVE-2026-66645?
CVE-2026-66645 is a Stored Cross Site Scripting (XSS) vulnerability in the Table Of Contents Block plugin (<= 1.5.0) exploitable by authenticated users with contributor-level access. Attackers can inject malicious scripts that execute when other users view the affected page. Updating to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-66645 Table Of Contents Block plaqininin 1.5.0 və aşağı versiyalarında Contributor səviyyəli istifadəçilər tərəfindən həyata keçirilə bilən Saxlanılmış XSS zəifliyidir. Bu zəiflikdən istifadə edərək, autentifikasiya olunmuş istifadəçi hədəf sayta zərərli skript yerləşdirə bilər. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin and user role does CVE-2026-66645 affect?
This vulnerability affects the Table Of Contents Block plugin (version 1.5.0 and below) and can be exploited by Contributor-level users.
How can CVE-2026-66645 be mitigated?
Updating the plugin to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.