TinyMCE Color Picker <= 1.1 - Missing Authorization

2014-04-28 00:00
Anonymous

Strategic Overview

Status
Patched in 1.2
Affected PluginTinyMCE Color Picker
Affected Version<= 1.1
CVSS5.3Medium
CVECVE-2014-3844
View all TinyMCE Color Picker vulnerabilities

Vulnerability Overview

The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOTE: some of these details are obtained from third party information.

Technical Analysis

REMEDIATION: Update to version 1.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C