Medium 6.1
2025-04-03< 2.1.11
LuckyWP Table of Contents <= 2.1.10 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
Minimum safe version
2.1.11
Update to 2.1.11 or later to address 6 fixable vulnerabilities
LuckyWP Table of Contents <= 2.1.10 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
CVE-2024-9641
CVE-2024-2218
WordPress LuckyWP Table of Contents Plugin <= 2.1.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-2953
CVE-2024-2119