Description
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.
Remediation
References
Related Vulnerabilities
WordPress Plugin Link Juice Keeper Cross-Site Scripting (2.0.2)
WordPress Plugin Backup Migration Information Disclosure (1.2.8)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2010-2094)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-34429)