WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in LuckyWP Table of Contents

Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).

6Reported vulnerabilities
6.1Highest CVSS score
2.1.14Latest version
100,000+Active installs

What to do now

Update LuckyWP Table of Contents to 2.1.11 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: April 16, 2025 / Tested up to WordPress: 6.7.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-9641 Medium 4.8 0.4% Before 2.1.7 2.1.7 December 12, 2024
CVE-2024-2218 Medium 4.6 0.3% Before 2.1.6 2.1.6 June 14, 2024
CVE-2025-2299 Medium 6.1 0.2% Before 2.1.11 2.1.11 April 3, 2025
CVE-2024-2119 Medium 6.1 0.4% Before 2.1.5 2.1.5 May 22, 2024
CVE-2023-6487 Medium 5.4 0.3% Before 2.1.5 2.1.5 May 22, 2024
CVE-2024-2953 Medium 4.8 0.3% Before 2.1.5 2.1.5 May 22, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.