f(x) TOC

f(x) TOC has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for f(x) TOC has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2023.

All of these findings were reported by István Márton. f(x) TOC is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.35.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all f(x) TOC vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2023-0490

f(x) TOC <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
f(x) TOC banner
Latestv1.1.0
5.0(5)
100/100
Last Updated
2016-08-01 (10y ago)
Active Installs
300+
Downloads
7,170
Requires WP
4.0+
Requires PHP
0+
Tested up to
WP 4.7.35
Created
2016-02-25 (11y ago)

f(x) TOC Simple Table Of Contents Plugin. Just add [toc] shortcode in content to display. This plugin will parse and grab all heading (h1 -h6) in your content and display it as structured table of contents (just like WikiPedia.org table of contents). Features: Super simple and easy to use. Auto create Table of contents by listing all your headings in your content. The GPL v2.0 or later license. 🙂 Use it to make something cool. Support available at Genbu Media. Shortcode Options: You can use several options in [toc] shortcode: title: to change the title of table of contents, as default is Table of contents. title_tag: element wrapper for the title, the default is h2. list: you can use ul for unordered list (default), or ol for ordered list. depth: list depth (numeric). the default is 6. Advance usage example using all the options: [toc title=”This page content:” title_tag=”strong” list=”ol” depth=”1&#8243;] Notes for developer: Github Development of this plugin is hosted at GitHub. Pull request and bug reports are welcome. Hooks List of hooks available in this plugin: filter: fx_toc_default_args (array) The default option for the shortcode. filter: fx_toc_output (string) HTML output of the shortcode.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C