Description
WordPress Plugin TinyMCE Color Picker is prone to multiple vulnerabilities, including cross-site request forgery and security bypass vulnerabilities. Exploiting these issues may allow an attacker to perform otherwise restricted actions and subsequently e.g. manipulate plugin settings. WordPress Plugin TinyMCE Color Picker version 1.1 is vulnerable.
Remediation
Update to plugin version 1.2 or latest
References
Related Vulnerabilities
XWiki Files or Directories Accessible to External Parties Vulnerability (CVE-2022-23621)
PrestaShop Improper Authentication Vulnerability (CVE-2020-4074)
WordPress Plugin WP Cost Estimation & Payment Forms Builder Multiple Vulnerabilities (9.642)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3747)
Apache Traffic Server Improper Access Control Vulnerability (CVE-2014-3624)