Just TinyMCE Custom Styles

Just TinyMCE Custom Styles has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Just TinyMCE Custom Styles has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nabil Irawan. Just TinyMCE Custom Styles is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.5.20.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Just TinyMCE Custom Styles vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-62871

Just TinyMCE Custom Styles <= 1.2.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Just TinyMCE Custom Styles banner
Latestv1.2.1

Just TinyMCE Custom Styles

Alex Prokopenko / JustCoded

Author

Alex Prokopenko / JustCoded

4.8(6)
96/100
Last Updated
2020-08-14 (6y ago)
Active Installs
1,000+
Downloads
20,208
Requires WP
4.3+
Requires PHP
0+
Tested up to
WP 5.5.20
Created
2016-07-20 (10y ago)

This plugin controls the TinyMce “style_formats” parameter. It allows adding custom formatters to the Wysiwyg editor. This is only a user interface to the standard feature, which is disabled by default and explained in the official documentation on codex.wordpress.org: https://codex.wordpress.org/TinyMCE_Custom_Styles Features Load Settings from DB or .json file from theme Enable/Disable some style_format features for more clean formatting Nice interface to quickly add your formats Ability to apply custom editor css for each rule separately You can group your styles for more clear usage Bootstrap preset: pre-defined bootstrap styles for editor. Example: Custom link class For example, you can define an addition dropdown option of the css classes for the link tag. To do so, create such row formatter:. Title: My Link Style Selector: a Classes: my-link-style Editor CSS: a.my-link-style { color:red; } Plugin Demo Presets We added special feature called “Presets” – these are pre-defined styles included inside the plugin. You can import them to your site with a single click. With presets we plan to add popular CSS framework classes to be able to use them inside the editor. We started with a Bootstrap preset, because it’s one of the most popular CSS framework right now. ISSUES TRACKER If you have any feedbacks or bugs found, please write to our GitHub issues tracker: https://github.com/justcoded/just-tinymce-custom-styles/issues

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C