Description
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
Published: 2026-07-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TinyMCE Templates plugin versions 4.8.1 and earlier contain a Contributor Sensitive Data Exposure vulnerability. The flaw allows a contributor to view and potentially exfiltrate sensitive information stored in or carried by templates. This leads to compromise of confidentiality for users whose data is embedded in templates. The CVE description does not explicitly state that an attacker must be a contributor; this inference is drawn from the terminology used.

Affected Systems

The vulnerability affects the TinyMCE Templates plugin developed by Takayuki Miyauchi. All releases up to and including version 4.8.1 are impacted. Site owners using any of these versions are at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to involve an attacker who can act as a plugin contributor, allowing upload or modification of templates to access hidden data. No additional exploitation conditions are noted in the description.

Generated by OpenCVE AI on August 4, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TinyMCE Templates plugin to the latest available version (greater than 4.8.1).
  • If the plugin is no longer needed, remove or deactivate it entirely to eliminate the exposure surface.
  • Restrict contributor permissions so that only trusted users can upload or edit templates, and review template content for sensitive data before publishing.

Generated by OpenCVE AI on August 4, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Takayuki Miyauchi
Takayuki Miyauchi tinymce Templates
Wordpress
Wordpress wordpress
Vendors & Products Takayuki Miyauchi
Takayuki Miyauchi tinymce Templates
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
Title WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Takayuki Miyauchi Tinymce Templates
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:37:26.146Z

Reserved: 2026-07-22T08:54:12.816Z

Link: CVE-2026-65535

cve-icon Vulnrichment

Updated: 2026-07-23T13:37:18.299Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:46.497

Modified: 2026-07-23T14:17:59.510

Link: CVE-2026-65535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere