Description
WordPress Plugin TinyMCE Color Picker is prone to multiple vulnerabilities, including cross-site request forgery and security bypass vulnerabilities. Exploiting these issues may allow an attacker to perform otherwise restricted actions and subsequently e.g. manipulate plugin settings. WordPress Plugin TinyMCE Color Picker version 1.1 is vulnerable.
Remediation
Update to plugin version 1.2 or latest
References
Related Vulnerabilities
WordPress Plugin Import any XML or CSV File to WordPress Arbitrary File Upload (3.2.3)
WordPress Plugin Quiz Tool Lite Multiple Cross-Site Scripting Vulnerabilities (2.3.15)
WordPress Plugin Admin Pack by SITE CASEIRO Cross-Site Scripting (1.1)
WordPress 5.1.x Multiple Vulnerabilities (5.1 - 5.1.5)
WordPress Plugin Zingiri Web Shop Unspecified Vulnerability (2.6.5)