TinyMCE Color Picker
TinyMCE Color Picker has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2014; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10. 2014 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for TinyMCE Color Picker has a vendor fix available, so running the current release closes all known holes.
TinyMCE Color Picker is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.9.40.
CVE-2014-3844TinyMCE Color Picker <= 1.1 - Missing Authorization
Read the full analysisVulnerability Records
TinyMCE Color Picker
Author
iseulde
This plugin adds and advanced color picker to the editor. You’ll have the ability to add custom colors with a color picker, a feature that has been removed from WordPress 3.9. It only works for WordPress 3.9 and higher.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C