Table of content
Table of content has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Table of content has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. Table of content is installed on roughly 90 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2025-58857Table of content <= 1.5.3.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Table of content
Author
KaizenCoders
Insert a table of content in your posts. You only have to insert the shortcode [toc] in your post to display the table of content. Please note that you can also configure a text to be inserted before the title of you post such as Chapter or Section with numbers. Plugin developped from the orginal plugin Toc for WordPress. This plugin is under GPL licence. Multisite – WordPress MU This plugin works with Multisite installation Localization German (Germany) translation provided by internetfreak, ChristopherKbel, GLassnig, K.R.Lembach English (United States), default language Spanish (Spain) translation provided by Jan-ErikFinlander Spanish (Mexico) translation provided by RobertoRamrez Finnish (Finland) translation provided by Jan-ErikFinlander French (France) translation provided by SedLex Italian (Italy) translation provided by jkappa, DipSTF Dutch (Netherlands) translation provided by MarcelJansen Romanian (Romania) translation provided by Adrian Russian (Russia) translation provided by Limych Features of the framework This plugin uses the SL framework. This framework eases the creation of new plugins by providing tools and frames (see dev-toolbox plugin for more info). You may easily translate the text of the plugin and submit it to the developer, send a feedback, or choose the location of the plugin in the admin panel. Have fun !
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C