
TinyMCE Color Picker Security & Risk Analysis
wordpress.org/plugins/tinymce-colorpickerThis plugin adds and advanced color picker to the editor. You’ll have the ability to add custom colors with a color picker, a feature that has been re …
Is TinyMCE Color Picker Safe to Use in 2026?
Mostly Safe
Score 84/100TinyMCE Color Picker is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The 'tinymce-colorpicker' v1.3 plugin exhibits a mixed security posture. Static analysis reveals a very small attack surface with all identified entry points having authentication and capability checks in place, along with proper SQL and output escaping. This indicates good development practices regarding these common vulnerability vectors. However, the vulnerability history is a significant concern. The plugin has two known medium-severity vulnerabilities, specifically Cross-Site Request Forgery (CSRF) and Missing Authorization. While none are currently unpatched, the recurrence of these issues suggests potential weaknesses in how the plugin handles user input and permissions, even with the presence of nonce and capability checks. The outdated bundled TinyMCE library is a minor concern, though not necessarily exploitable in itself without further vulnerabilities.
Key Concerns
- Known medium-severity CVEs (2)
- Bundled outdated library: TinyMCE v1.3
TinyMCE Color Picker Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
TinyMCE Color Picker < 1.2 - Cross-Site Request Forgery
TinyMCE Color Picker <= 1.1 - Missing Authorization
TinyMCE Color Picker Code Analysis
Bundled Libraries
TinyMCE Color Picker Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
TinyMCE Color Picker Maintenance & Trust
Maintenance Signals
Community Trust
TinyMCE Color Picker Alternatives
Black Studio TinyMCE Widget
black-studio-tinymce-widget
The visual editor widget for WordPress.
AddQuicktag
addquicktag
This plugin makes it easy to add Quicktags to the html - and visual-editor.
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
post-and-page-builder
Post and Page Builder is a standalone plugin which adds functionality to the existing TinyMCE Editor.
TinyMCE Templates
tinymce-templates
TinyMCE Template plugin will enable to use HTML template on WordPress Visual Editor.
Visual Term Description Editor
visual-term-description-editor
Replaces the plain-text category and tag description editor with a visual editor.
TinyMCE Color Picker Developer Profile
1 plugin · 1K total installs
How We Detect TinyMCE Color Picker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinymce-colorpicker/tinymce-colorpicker.js/wp-content/plugins/tinymce-colorpicker/tinymce-colorpicker.csstinymce-colorpicker.jsHTML / DOM Fingerprints
tinymce_cp__mce_external_pluginstinymce_cp__wp_enqueue_editortinymce_cp__tiny_mce_before_inittinymce_cp__mce_buttons_2tinymce_cp__update_optiontinyMCEColorPicker/wp-json/tinymce-colorpicker