Description
Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just TinyMCE Custom Styles just-tinymce-styles allows Cross Site Request Forgery.This issue affects Just TinyMCE Custom Styles: from n/a through <= 1.2.1.
Published: 2025-12-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw exists in the Just TinyMCE Custom Styles WordPress plugin when its version is 1.2.1 or older. The vulnerability allows an attacker to trick a legitimate user into performing unintended actions via forged HTTP requests. The CVE description indicates a CSRF vulnerability, which is inferred to arise from a missing anti‑CSRF token, aligning with CWE‑352. The impact is limited to actions that the victim is authorized to perform; an attacker could, for example, cause content changes or activate plugin settings without explicit consent. This poses a moderate confidentiality and integrity risk for the targeted site, but it does not directly allow code execution or system compromise.

Affected Systems

WordPress sites that have installed the Just TinyMCE Custom Styles plugin by Alex Prokopenko / JustCoded, version 1.2.1 or earlier. No additional product or version details are supplied by the CNA, and a vulnerable instance exists as soon as the plugin is in use on the site. Sites running newer versions or without the plugin are not affected.

Risk and Exploitability

The CVSS score of 4.3 indicates the bug is considered low‑to‑moderate severity. The EPSS score of less than 1% further suggests that exploitation probability is very low. The vulnerability is not listed in the CISA KEV catalog. A likely attack vector would be a user visiting a specially crafted page or an attacker sending a crafted link to a logged‑in administrator, thereby forcing a state‑changing request. No specific authentication or privilege escalation is required beyond the normal user session that delivers the forged request.

Generated by OpenCVE AI on April 29, 2026 at 16:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Just TinyMCE Custom Styles plugin to a version above 1.2.1, if one is available in the WordPress plugin repository.
  • If an upgrade is not possible, remove or disable the plugin from the WordPress installation to eliminate the CSRF vector.
  • Perform a security review of other active plugins for missing CSRF protections, prioritizing those that perform state‑changing actions.

Generated by OpenCVE AI on April 29, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just TinyMCE Custom Styles just-tinymce-styles allows Cross Site Request Forgery.This issue affects Just TinyMCE Custom Styles: from n/a through <= 1.2.1.
Title WordPress Just TinyMCE Custom Styles plugin <= 1.2.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:56:36.032Z

Reserved: 2025-10-24T07:50:53.684Z

Link: CVE-2025-62871

cve-icon Vulnrichment

Updated: 2025-12-10T22:03:16.310Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:04.203

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:15:15Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)