LuckyWP Table of Contents

LuckyWP Table of Contents has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 5 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.1 out of 10. 2024 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (100%).

Every one of the 5 issues recorded for LuckyWP Table of Contents has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, one record each. LuckyWP Table of Contents is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all LuckyWP Table of Contents vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-2299

LuckyWP Table of Contents <= 2.1.10 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

5 records
LuckyWP Table of Contents banner
Latestv2.1.14

LuckyWP Table of Contents

LuckyWP

Author

LuckyWP

4.9(885)
98/100
Last Updated
2025-04-16 (1y ago)
Active Installs
100,000+
Downloads
1,138,478
Requires WP
4.7+
Requires PHP
5.6.20+
Tested up to
WP 6.7.7
Created
2018-11-14 (8y ago)

Creates SEO-friendly table of contents for your posts, pages or custom post types. Great customizable appearance. Features Automatical insertion a table of contents (configure post types and position). SEO-friendly: table of contents code is ready to use by Google for snippets on result page. Insert by shortcode, Gutenberg block or widget. Button on toolbar of the classic editor. Gutenberg block into “Common Blocks”. Setting the minimum number of headings to display table of contents. Setting the depth of headings for table of contents. Skip headings by level or text. Hierarchical or linear view. Numeration items: decimal or roman numbers in order or nested. Customizable appearance: width, float, title font size and weight, items font size, colors. Color schemes (dark, light, white, transparent, inherit from theme) and the ability to override colors. Toggle Show/Hide (optionally) Customizable labels. Smooth scroll (optionally). Setting offset top for smooth scroll. Wrap table of contents with <!–noindex–> tag (optionally). Pretty hash in URL (like example.com/faq/#how_do_this). RTL support. Available override global settings for a particular post. Highly compatible with WordPress themes and plugins. Auto Insert For automatical insertion a table of contents in a posts, select option “Auto Insert Table of Contents” in the plugin settings (tab “Auto Insert”). Supported positions: before first heading; after first heading; after first block (paragraph or heading); top of post content; bottom of post content. You can also select post types to which the table of contents will be automatically added. Manual Insert For manual insertion a table of content in a posts, use one of the ways: button “Table of Contents” on toolbar in classic editor; gutenberg block “Table of Contents”; shortcode [lwptoc]. Pretty hash in URL By default, hash generated as heading text (for example, #How_Do_This). You can change hash format in global settings, tab “Misc.”. For non-English websites it is recommended to enable the Intl PHP extension. Compatibility LuckyWP Table of Contents was successfully tested with the following plugins: Elementor Page Builder Beaver Builder and Beaver Builder Themer Add-On WPBakery Page Builder Oxygen WordPress Multilingual Plugin (WPML), officially confirmed Rank Math, officially confirmed WP Rocket Toolset Views and Toolset Access Hooks Filters lwptoc_before, lwptoc_after Use for add custom HTML before/after the table of contents. Example: add_filter('lwptoc_before', function ($before) { return '<p>Example text before TOC.</p>' . $before; }); Filter lwptoc_shortcode_tag Use this filter for change shortcode tag name [lwptoc]. Example: add_filter('lwptoc_shortcode_tag', function ($tag) { return 'toc'; }); Filter lwptoc_heading_id Use for modify heading ID. Example: add_filter('lwptoc_heading_id', function ($id, $label) { return $id; }, 10, 2);

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C