plugin

Crayon Syntax Highlighter Vulnerabilities

18 known security issues reported for the Crayon Syntax Highlighter WordPress plugin. Most recent disclosed Sep 12, 2023.

1 critical 1 high 4 medium

Running Crayon Syntax Highlighter on your site? Check whether your installed version is affected.

Scan your site free

Crayon Syntax Highlighter [crayon-syntax-highlighter] <= 2.8.4 (unfixed + closed)

unknown

[en] The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web...

Affected:
up to 2.8.4
Fix:
No patched version reported
Disclosed:
Sep 12, 2023

CVE-2023-4893 on NVD →

Crayon Syntax Highlighter <= 2.8.4 - Authenticated (Contributor+) Server Side Request Forgery

medium

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web appl...

CVSS:
6.4
Affected:
up to 2.8.4
Fix:
No patched version reported
Disclosed:
Sep 11, 2023

CVE-2023-4893 on NVD →

Crayon Syntax Highlighter [crayon-syntax-highlighter] <= 2.8.4 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Aram Kocharyan Crayon Syntax Highlighter plugin <= 2.8.4 versions.

Affected:
up to 2.8.4
Fix:
No patched version reported
Disclosed:
May 22, 2023

CVE-2022-47167 on NVD →

Crayon Syntax Highlighter <= 2.8.4 - Cross-Site Request Forgery

high

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.4. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted t...

CVSS:
8.8
Affected:
up to 2.8.4
Fix:
No patched version reported
Disclosed:
Jan 13, 2023

CVE-2022-47167 on NVD →

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.8.4 (closed)

unknown

[en] The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Aug 20, 2019

CVE-2016-10893 on NVD →

Crayon Syntax Highlighter < 2.8.4 - Cross-Site Scripting

medium

The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.

CVSS:
6.1
Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
May 10, 2016

CVE-2016-10893 on NVD →

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)

unknown

This plugin is prone to a local file disclosure vulnerability. It allows attackers to see the content of any file. Update plugin.

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
May 15, 2015

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)

unknown

Because of this vulnerability, attackers can craft the user provided parameters in such a way that it becomes possible to overwrite base themes with arbitrary CSS. Update plugin.

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
May 15, 2015

Crayon Syntax Highlighter 2.0 - 2.6.10 - Missing Authorization

medium

The Crayon Syntax Highlighter Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the crayon-theme-editor-save AJAX action in versions 2.0 - 2.6.10. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to overwrite theme files.

CVSS:
5.4
Affected:
2.0 – 2.6.10
Fixed in:
2.7.0
Disclosed:
Apr 20, 2015

Crayon Syntax Highlighter [crayon-syntax-highlighter] >= 2.0 - <= 2.6.10 (closed)

unknown

The Crayon Syntax Highlighter Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the crayon-theme-editor-save AJAX action in versions 2.0 - 2.6.10. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to overwrite theme files.

Affected:
2.0 – 2.6.10
Fixed in:
2.6.10
Disclosed:
Apr 20, 2015

Crayon Syntax Highlighter <= 2.6.10 - Directory Traversal

medium

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 2.6.10 via the 'data-url' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, potentially outside the web root, which can contain sensitive inform...

CVSS:
6.5
Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Apr 14, 2015

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)

unknown

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 2.6.10 via the 'data-url' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, potentially outside the web root, which can contain sensitive inform...

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Apr 14, 2015

Crayon Syntax Highlighter Plugin <= 1.13 - Remote File Inclusion

critical

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.13 via the crayon_is_php_file function. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.

CVSS:
9.8
Affected:
up to 1.13
Fixed in:
1.14
Disclosed:
Oct 15, 2012

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 1.12.2 (closed)

unknown

WordPress Crayon Syntax Highlighter plugin's "wp_load" parameter is prone to a remote file include vulnerability. It allows an attacker o compromise the application and the underlying system. Other attacks are also possible. Update the plugin.

Affected:
up to 1.12.2
Fixed in:
1.12.2
Disclosed:
Oct 15, 2012

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 1.14 (closed)

unknown

The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.13 via the crayon_is_php_file function. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.

Affected:
up to 1.14
Fixed in:
1.14
Disclosed:
Oct 15, 2012

Crayon Syntax Highlighter [crayon-syntax-highlighter] >= 2.0 - <= 2.6.10 (closed)

unknown

The Crayon Syntax Highlighter plugin allows access to the AJAX method &#039;crayon-theme-editor-save&#039; to any registered user. When called, the AJAX method &lsquo;crayon-theme-editor-save&rsquo; will call the &#039;save&#039; function within the CrayonThemeEditorWP class, defined in &#039;crayon-syntax-highlighter/...

Affected:
2.0 – 2.6.10
Fixed in:
2.6.10

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 2.7.0 (closed)

unknown

The local file syntax highlighting feature of Crayon Syntax Highlighter doesn&#039;t check the path of the file to process. Also, by default, this feature is usable through public comments. This allows unauthenticated visitors to see the content of any file where the web server has read permissions, such as PHP source...

Affected:
up to 2.7.0
Fixed in:
2.7.0

Crayon Syntax Highlighter [crayon-syntax-highlighter] < 1.13 (closed)

unknown

The Crayon Syntax Highlighter WordPress plugin was affected by a Remote File Inclusion security vulnerability.

Affected:
up to 1.13
Fixed in:
1.13

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database