plugin

Revision Manager Tmc Vulnerabilities

6 known security issues reported for the Revision Manager Tmc WordPress plugin. Most recent disclosed Feb 19, 2026.

1 high 2 medium

Running Revision Manager Tmc on your site? Check whether your installed version is affected.

Scan your site free

Revision Manager TMC [revision-manager-tmc] <= 2.8.22 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in themastercut Revision Manager TMC revision-manager-tmc allows Cross Site Request Forgery.This issue affects Revision Manager TMC: from n/a through <= 2.8.22.

Affected:
up to 2.8.22
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25411 on NVD →

Revision Manager TMC <= 2.8.22 - Cross-Site Request Forgery

medium

The Revision Manager TMC plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.22. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...

CVSS:
4.3
Affected:
up to 2.8.22
Fix:
No patched version reported
Disclosed:
Jan 28, 2026

CVE-2026-25411 on NVD →

Revision Manager TMC <= 2.8.19 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending

medium

The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 2.8.19
Fixed in:
2.8.20
Disclosed:
Sep 6, 2024

CVE-2024-7622 on NVD →

Revision Manager TMC [revision-manager-tmc] < 2.8.20

unknown

[en] The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and ab...

Affected:
up to 2.8.20
Fixed in:
2.8.20
Disclosed:
Sep 6, 2024

CVE-2024-7622 on NVD →

Revision Manager TMC [revision-manager-tmc] < 2.8.0

unknown

[en] jqueryFileTree 2.1.5 and older Directory Traversal

Affected:
up to 2.8.0
Fixed in:
2.8.0
Disclosed:
Nov 17, 2017

CVE-2017-1000170 on NVD →

JQueryFileTree <= 2.1.5 - Directory Traversal

high

Several WordPress plugins using the JqueryFileTree extension are vulnerable to Directory Traversal via the 'dir' parameter in various versions. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 2.7.91
Fixed in:
2.8.0
Disclosed:
May 8, 2017

CVE-2017-1000170 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database