CVE-2025-1286: Download HTML TinyMCE Button <= 1.2 - Reflected XSS
The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1286?
CVE-2025-1286 is classified as a high severity vulnerability due to its potential to allow reflected cross-site scripting attacks against high privilege users.
How do I fix CVE-2025-1286?
To fix CVE-2025-1286, you should update the Download HTML TinyMCE Button plugin to version 1.3 or later, which includes the necessary sanitization and escaping improvements.
Who is affected by CVE-2025-1286?
CVE-2025-1286 affects users of the Download HTML TinyMCE Button WordPress plugin up to version 1.2, particularly targeting high privilege users such as administrators.
What kind of attacks can CVE-2025-1286 be used for?
CVE-2025-1286 can be exploited for reflected cross-site scripting attacks, potentially allowing an attacker to execute scripts in the context of an affected user's session.
Is there a workaround for CVE-2025-1286?
There are no known workarounds for CVE-2025-1286; the best course of action is to update to a patched version of the plugin.