Lucene search

K
wpvulndbWpvulndbWPVDB-ID:683781CE-383E-48CF-846D-7E8B6129C94A
HistoryJan 27, 2023 - 12:00 a.m.

TinyMCE Custom Styles < 1.1.3 - Admin+ Stored XSS

2023-01-2700:00:00
wpscan.com
3
tinymce
custom styles
stored xss
admin
settings
high privilege
cross-site scripting
unfiltered html
multisite setup
security issue

0.0005 Low

EPSS

Percentile

17.7%

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CPENameOperatorVersion
tinymce-custom-styleslt1.1.3

0.0005 Low

EPSS

Percentile

17.7%

Related for WPVDB-ID:683781CE-383E-48CF-846D-7E8B6129C94A