Executive brief
TinyMCE Templates is a WordPress plugin used to create and manage reusable content templates within the post editor. A security flaw in versions 4.8.1 and earlier allows users with 'Contributor' level access to view sensitive system information that should normally be restricted. This exposure could potentially be used by an internal user to gather intelligence for further attacks on the website.
Technical details
The TinyMCE Templates plugin for WordPress (versions <= 4.8.1) suffers from an information disclosure vulnerability (CWE-497). The flaw allows authenticated attackers with Contributor-level permissions to access sensitive system information that is not intended for their privilege level. The vulnerability is reachable over the network without user interaction, provided the attacker has valid credentials. As of the advisory date, no official patch has been released by the developer. The vulnerability is classified as having a low impact on confidentiality with no impact on integrity or availability.
Affected products
- Takayuki Miyauchi TinyMCE Templates <= 4.8.1
Timeline
- 2026-06-12: other: Vulnerability reported by researcher Ananda Dhakal
- 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD