Input validation vulnerability in TinyMCE Custom Styles 1.1.3

The TinyMCE Custom Styles plugin for WordPress is vulnerable to potential security risks in versions up to 1.1.3. This vulnerability could allow anyone with administrative-level permissions or higher to inject malicious web scripts into pages, which would then execute whenever a user visits the page. This vulnerability only affects multi-site installations and installations where the ‘unfiltered_html’ setting has been disabled.

Detected in:

TinyMCE Custom Styles fixed vulnerable versions: >= * <= 1.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.