CVE-2018-5311: Tonjoostudio Easy Custom Auto Excerpt

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI.

Affected products

Published 2018-01-09. Last modified 2026-06-17.