Crayon Syntax Highlighter [crayon-syntax-highlighter] <= 2.8.4 (unfixed + closed)
unknown
[en] The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web...
- Affected:
- up to 2.8.4
- Fix:
- No patched version reported
- Disclosed:
- Sep 12, 2023
CVE-2023-4893 on NVD →
Crayon Syntax Highlighter <= 2.8.4 - Authenticated (Contributor+) Server Side Request Forgery
medium
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web appl...
- CVSS:
- 6.4
- Affected:
- up to 2.8.4
- Fix:
- No patched version reported
- Disclosed:
- Sep 11, 2023
CVE-2023-4893 on NVD →
Crayon Syntax Highlighter [crayon-syntax-highlighter] <= 2.8.4 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Aram Kocharyan Crayon Syntax Highlighter plugin <= 2.8.4 versions.
- Affected:
- up to 2.8.4
- Fix:
- No patched version reported
- Disclosed:
- May 22, 2023
CVE-2022-47167 on NVD →
Crayon Syntax Highlighter <= 2.8.4 - Cross-Site Request Forgery
high
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.4. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted t...
- CVSS:
- 8.8
- Affected:
- up to 2.8.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 13, 2023
CVE-2022-47167 on NVD →
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.8.4 (closed)
unknown
[en] The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Aug 20, 2019
CVE-2016-10893 on NVD →
Crayon Syntax Highlighter < 2.8.4 - Cross-Site Scripting
medium
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
- CVSS:
- 6.1
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- May 10, 2016
CVE-2016-10893 on NVD →
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)
unknown
This plugin is prone to a local file disclosure vulnerability. It allows attackers to see the content of any file.
Update plugin.
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- May 15, 2015
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)
unknown
Because of this vulnerability, attackers can craft the user provided parameters in such a way that it becomes possible to overwrite base themes with arbitrary CSS.
Update plugin.
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- May 15, 2015
Crayon Syntax Highlighter 2.0 - 2.6.10 - Missing Authorization
medium
The Crayon Syntax Highlighter Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the crayon-theme-editor-save AJAX action in versions 2.0 - 2.6.10. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to overwrite theme files.
- CVSS:
- 5.4
- Affected:
- 2.0 – 2.6.10
- Fixed in:
- 2.7.0
- Disclosed:
- Apr 20, 2015
Crayon Syntax Highlighter [crayon-syntax-highlighter] >= 2.0 - <= 2.6.10 (closed)
unknown
The Crayon Syntax Highlighter Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the crayon-theme-editor-save AJAX action in versions 2.0 - 2.6.10. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to overwrite theme files.
- Affected:
- 2.0 – 2.6.10
- Fixed in:
- 2.6.10
- Disclosed:
- Apr 20, 2015
Crayon Syntax Highlighter <= 2.6.10 - Directory Traversal
medium
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 2.6.10 via the 'data-url' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, potentially outside the web root, which can contain sensitive inform...
- CVSS:
- 6.5
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Apr 14, 2015
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)
unknown
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 2.6.10 via the 'data-url' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, potentially outside the web root, which can contain sensitive inform...
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Apr 14, 2015
Crayon Syntax Highlighter Plugin <= 1.13 - Remote File Inclusion
critical
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.13 via the crayon_is_php_file function. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.
- CVSS:
- 9.8
- Affected:
- up to 1.13
- Fixed in:
- 1.14
- Disclosed:
- Oct 15, 2012
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 1.12.2 (closed)
unknown
WordPress Crayon Syntax Highlighter plugin's "wp_load" parameter is prone to a remote file include vulnerability. It allows an attacker o compromise the application and the underlying system. Other attacks are also possible.
Update the plugin.
- Affected:
- up to 1.12.2
- Fixed in:
- 1.12.2
- Disclosed:
- Oct 15, 2012
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 1.14 (closed)
unknown
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.13 via the crayon_is_php_file function. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.
- Affected:
- up to 1.14
- Fixed in:
- 1.14
- Disclosed:
- Oct 15, 2012
Crayon Syntax Highlighter [crayon-syntax-highlighter] >= 2.0 - <= 2.6.10 (closed)
unknown
The Crayon Syntax Highlighter plugin allows access to the AJAX method 'crayon-theme-editor-save' to any registered user. When called, the AJAX method ‘crayon-theme-editor-save’ will call the 'save' function within the CrayonThemeEditorWP class, defined in 'crayon-syntax-highlighter/...
- Affected:
- 2.0 – 2.6.10
- Fixed in:
- 2.6.10
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)
unknown
The local file syntax highlighting feature of Crayon Syntax Highlighter doesn't check the path of the file to process. Also, by default, this feature is usable through public comments. This allows unauthenticated visitors to see the content of any file where the web server has read permissions, such as PHP source...
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
Crayon Syntax Highlighter [crayon-syntax-highlighter] < 1.13 (closed)
unknown
The Crayon Syntax Highlighter WordPress plugin was affected by a Remote File Inclusion security vulnerability.
- Affected:
- up to 1.13
- Fixed in:
- 1.13
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database