TinyMCE 4.3.8 XSS PoC

As far as I know, if you are using Preview Plugin, your application is vulnerable to XSS.

Steps to Reproduce

  1. Open this page using IE/Edge.
  2. Click here.
  3. Click "View" menu → "Preview". Done!