Make WordPress Core

Opened 2 weeks ago

Closed 2 weeks ago

#65954 closed defect (bug) (duplicate)

TinyMCE out of date

Reported by: prachi2patel Owned by:
Priority: normal Milestone:
Component: General Version:
Severity: normal Keywords:
Cc: Focuses:

Description

Regarding ticket #65906, I understand that it was closed as a duplicate of #47218 and that WordPress has decided not to upgrade TinyMCE.

However, I would like to clarify the security implications. In the #47218 discussion, I can see that CVE-2022-23494 was discussed and that it could not be reproduced in WordPress. However, I could not find any WordPress confirmation or analysis regarding the other CVEs identified in our security scan, including:

CVE-2024-29203
CVE-2024-29881
CVE-2026-47759
CVE-2026-47761
CVE-2026-47762
CVE-2024-21911
CVE-2024-21910
CVE-2023-45819
CVE-2023-45818
CVE-2024-21908
CVE-2023-48219

Could you please confirm whether these CVEs have been assessed for the version of TinyMCE bundled with WordPress and whether they are applicable or exploitable in the WordPress environment?

If they are not applicable to WordPress, could you please provide an official reference or explanation for each CVE so that we can document the finding with our security team?

I understand that the decision not to upgrade TinyMCE is intentional, but I am specifically looking for confirmation regarding the security applicability of the individual CVEs, rather than confirmation of the decision not to upgrade TinyMCE.

Change History (1)

#1 @ocean90
2 weeks ago

  • Milestone Awaiting Review
  • Priority highnormal
  • Resolutionduplicate
  • Status newclosed
  • Version 7.1

Duplicate of #47218.

Discussions can happen on closed tickets as well. To keep them in one place I’m closing this one as a duplicate too.

If you believe you have found a vulnerability in WordPress, please keep it confidential and report it to the WordPress Security Team.

Note: See TracTickets for help on using tickets.