Ultimate TinyMCE [ultimate-tinymce] <= 5.7 (unfixed + closed)
unknown
[en] The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inje...
- Affected:
- up to 5.7
- Fix:
- No patched version reported
- Disclosed:
- Oct 30, 2024
CVE-2024-8627 on NVD →
Ultimate TinyMCE <= 5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject ar...
- CVSS:
- 6.4
- Affected:
- up to 5.7
- Fix:
- No patched version reported
- Disclosed:
- Oct 29, 2024
CVE-2024-8627 on NVD →
Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)
unknown
Update plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TinyMCE Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your s...
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- May 15, 2023
Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update plugin.
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- May 15, 2015
Ultimate TinyMCE < 3.6 - Cross-Site Scripting
medium
The Ultimate TinyMCE plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Aug 1, 2014
Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)
unknown
The Ultimate TinyMCE plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Aug 1, 2014
Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Jul 19, 2013
CVE-2012-3414 on NVD →
SWFUpload <= 2.2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 6.1
- Affected:
- up to 3.5
- Fixed in:
- 3.6
- Disclosed:
- Nov 9, 2012
CVE-2012-3414 on NVD →
Ultimate TinyMCE [ultimate-tinymce] < 3.6 (closed)
unknown
The Ultimate TinyMCE WordPress plugin was affected by a swfupload Cross-Site Scripting security vulnerability.
- Affected:
- up to 3.6
- Fixed in:
- 3.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database