The Custom Tinymce Shortcode Button Project maintains a WordPress plugin that extends the TinyMCE editor with shortcode insertion functionality, a narrowly scoped addition to the WordPress editing ecosystem. The observed vulnerability pattern centers on cross-site scripting issues, reflecting the input-handling risks inherent to a tool that processes and generates shortcodes within the editor context.
The number and severity of CVEs published that impact products developed by Custom Tinymce Shortcode Button Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1217MEDIUM The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, lead | May 16, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Custom Tinymce Shortcode Button Project.
Media articles that mention a CVE ID that affects a product developed by Custom Tinymce Shortcode Button Project — matched by CVE ID, not by vendor name.