CVE-2025-15694
âšī¸ lowSummary
The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.
CVSS Score
3.5
Low
EPSS Score
0.2
Exploit Probability
Published Date
2026-09-05
First Seen: 2026-09-06
đ Relative Risk Intelligence
This CVE is Lower Risk - more severe than 3.8% of all 353,175 vulnerabilities in our database.
#339,793
Below average severity
Severity Percentile
đ¯ CISA SSVC Assessment Updated: Sep 6, 2026
đ Exploitation Status
None
No known exploits
âī¸ Automatable
NO
Requires human interaction
đĨ Technical Impact
Partial
Limited system impact
đ Discovered By
Krugov Artyom
WPScan (coordinator)
SSVC data provided by
CISA
Last Modified
2026-09-06
Source
NVD đ
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
CWE IDs (Weakness Types)