Revision Manager TMC [revision-manager-tmc] <= 2.8.22 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in themastercut Revision Manager TMC revision-manager-tmc allows Cross Site Request Forgery.This issue affects Revision Manager TMC: from n/a through <= 2.8.22.
- Affected:
- up to 2.8.22
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25411 on NVD →
Revision Manager TMC <= 2.8.22 - Cross-Site Request Forgery
medium
The Revision Manager TMC plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.22. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 2.8.22
- Fix:
- No patched version reported
- Disclosed:
- Jan 28, 2026
CVE-2026-25411 on NVD →
Revision Manager TMC <= 2.8.19 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
medium
The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 2.8.19
- Fixed in:
- 2.8.20
- Disclosed:
- Sep 6, 2024
CVE-2024-7622 on NVD →
Revision Manager TMC [revision-manager-tmc] < 2.8.20
unknown
[en] The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- Affected:
- up to 2.8.20
- Fixed in:
- 2.8.20
- Disclosed:
- Sep 6, 2024
CVE-2024-7622 on NVD →
Revision Manager TMC [revision-manager-tmc] < 2.8.0
unknown
[en] jqueryFileTree 2.1.5 and older Directory Traversal
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Nov 17, 2017
CVE-2017-1000170 on NVD →
JQueryFileTree <= 2.1.5 - Directory Traversal
high
Several WordPress plugins using the JqueryFileTree extension are vulnerable to Directory Traversal via the 'dir' parameter in various versions. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 2.7.91
- Fixed in:
- 2.8.0
- Disclosed:
- May 8, 2017
CVE-2017-1000170 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database