Vulnerabilities > Tinymce > Color Picker

DATE CVE VULNERABILITY TITLE RISK
2014-05-22 CVE-2014-3845 Cross-Site Request Forgery (CSRF) vulnerability in Tinymce Color Picker
Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors.
6.8
2014-05-22 CVE-2014-3844 Permissions, Privileges, and Access Controls vulnerability in Tinymce Color Picker
The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors.
network
low complexity
tinymce wordpress CWE-264
5.0