QID 730942
Date Published: 2023-11-20
QID 730942: WordPress Plugin TinyMCE Custom Styles Stored Cross-Site Scripting (XSS) Vulnerability
Tutor LMS is a complete, feature-packed, and robust WordPress LMS plugin to easily create and sell courses online.
CVE-2023-2967: WordPress plugin TinyMCE Custom Styles versions before 1.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Affected Versions:
WordPress TinyMCE Custom Styles Plugin versions prior to 1.1.4
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for TinyMCE Custom Styles Plugin using readme.txt.
Successful exploitation of this vulnerability may allow high privileged user to execute arbitrary JavaScript code on the target system.
- TinyMCE Custom Styles Plugin Release Notes -
wordpress.org/plugins/tinymce-custom-styles/#developers
CVEs related to QID 730942
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TinyMCE Custom Styles Plugin Release Notes |
|