
CVE-2025-13738 The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including,… https://www.cve.org/CVERecord?id=CVE-2025-13738
Post summary
The Easy Table of Contents WordPress plugin is vulnerable to stored XSS via its ez‑toc shortcode (CVE‑2025‑13738). No exploit, patch, or active exploitation details are provided.
