CVE-2024-25904 MEDIUM

CVE-2024-25904: WordPress TinyMCE Professional Formats and Styles Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF)

Vendor David Stockl
Product TinyMCE and TinyMCE Advanced Professsional Formats and Styles
Weakness CWE-352 · CSRF
Published February 21, 2024
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects TinyMCE and TinyMCE Advanced Professsional Formats and Styles: from n/a through 1.1.2.

Explanation of Vulnerability in Simple Terms

02Summary

A cross-site request forgery (CSRF) vulnerability in TinyMCE Advanced Professional Formats and Styles allows an attacker to perform unwanted actions on behalf of a logged-in user. The vulnerability requires the user to visit a malicious webpage while authenticated. An attacker can modify site content or settings through forged requests, but cannot read sensitive data.

What an attacker can do

03Attacker Capabilities

Perform unwanted actions (like modifying content) on behalf of a logged-in site user.

Potential impact on your site

04Site Impact

Site content or editor settings could be altered without the user's knowledge if they visit a malicious link while logged in.

Conditions required to exploit

05Prerequisites

User must be logged in and visit an attacker-controlled webpage while authenticated.

Key dates

06Disclosure timeline

February 21, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE