VYPR
Medium severity5.4NVD Advisory· Published Dec 9, 2024· Updated Apr 28, 2026

CVE-2023-25469

CVE-2023-25469

Description

Missing Authorization vulnerability in Magazine3 Easy Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Table of Contents: from n/a through 2.0.45.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Easy Table of Contents plugin <=2.0.45.2 has a missing authorization vulnerability allowing unprivileged users to perform higher-privileged actions.

Vulnerability

Overview The Easy Table of Contents plugin for WordPress, versions prior to 2.0.45.2, contains a missing authorization vulnerability. The plugin fails to properly enforce access controls, allowing unprivileged users to execute functions that should require higher privileges [1].

Exploitation

This broken access control issue can be exploited by any unauthenticated or low-privileged user who can send crafted requests to the affected plugin. The vulnerability is particularly dangerous because it can be used in mass-exploit campaigns targeting thousands of websites simultaneously, regardless of site popularity or traffic [1].

Impact

While the vulnerability is rated as low severity and considered unlikely to be exploited, it still poses a risk. An attacker could potentially access sensitive information or perform unauthorized actions, depending on the specific missing authorization checks. The CVSS score is 5.4 (Medium) [1].

Mitigation

Users are strongly advised to update the Easy Table of Contents plugin to version 2.0.46 or later, which contains the fix. For those unable to update immediately, Patchstack has issued a mitigation rule to block attacks until the update is applied [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.