plugin

Ultimate Tinymce Vulnerabilities

9 known security issues reported for the Ultimate Tinymce WordPress plugin. Most recent disclosed Oct 30, 2024.

3 medium

Running Ultimate Tinymce on your site? Check whether your installed version is affected.

Scan your site free

Ultimate TinyMCE [ultimate-tinymce] <= 5.7 (unfixed + closed)

unknown

[en] The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inje...

Affected:
up to 5.7
Fix:
No patched version reported
Disclosed:
Oct 30, 2024

CVE-2024-8627 on NVD →

Ultimate TinyMCE <= 5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject ar...

CVSS:
6.4
Affected:
up to 5.7
Fix:
No patched version reported
Disclosed:
Oct 29, 2024

CVE-2024-8627 on NVD →

Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)

unknown

Update plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TinyMCE Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your s...

Affected:
up to 3.6
Fixed in:
3.6
Disclosed:
May 15, 2023

Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 3.6
Fixed in:
3.6
Disclosed:
May 15, 2015

Ultimate TinyMCE < 3.6 - Cross-Site Scripting

medium

The Ultimate TinyMCE plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 3.6
Fixed in:
3.6
Disclosed:
Aug 1, 2014

Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)

unknown

The Ultimate TinyMCE plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 3.6
Fixed in:
3.6
Disclosed:
Aug 1, 2014

Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

Affected:
up to 3.6
Fixed in:
3.6
Disclosed:
Jul 19, 2013

CVE-2012-3414 on NVD →

SWFUpload <= 2.2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
6.1
Affected:
up to 3.5
Fixed in:
3.6
Disclosed:
Nov 9, 2012

CVE-2012-3414 on NVD →

Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)

unknown

The Ultimate TinyMCE WordPress plugin was affected by a swfupload Cross-Site Scripting security vulnerability.

Affected:
up to 3.6
Fixed in:
3.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database