Permission Bypass in TinyMCE Color Picker Plugin for WordPress
CVE-2014-3844
Currently unrated
Summary
The TinyMCE Color Picker plugin for WordPress prior to version 1.2 contains a vulnerability due to improper permission checks. This weakness allows remote attackers to alter plugin settings without proper authorization, creating potential exploitation vectors. Users of this plugin should consider updating to the latest version to mitigate risks associated with unauthorized changes.
References
Timeline
Vulnerability Reserved
Vulnerability published