WP-GeSHi-Highlight <= 1.4.3 Authenticated (Author+) ReDoS
mediumThe WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages plugin for WordPress is vulnerable to Regex denial of service in all versions up to, and including, 1.4.3. This is due to the plugin not properly restricting regexes supplied to the wp_geshi_filter_replace_code() function. This makes it possible...
- CVSS:
- 4.3
- Affected:
- up to 1.4.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 20, 2025