Impact
The TinyMCE Templates plugin versions 4.8.1 and earlier contain a Contributor Sensitive Data Exposure vulnerability. The flaw allows a contributor to view and potentially exfiltrate sensitive information stored in or carried by templates. This leads to compromise of confidentiality for users whose data is embedded in templates. The CVE description does not explicitly state that an attacker must be a contributor; this inference is drawn from the terminology used.
Affected Systems
The vulnerability affects the TinyMCE Templates plugin developed by Takayuki Miyauchi. All releases up to and including version 4.8.1 are impacted. Site owners using any of these versions are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to involve an attacker who can act as a plugin contributor, allowing upload or modification of templates to access hidden data. No additional exploitation conditions are noted in the description.
OpenCVE Enrichment