WP-Syntax <= 1.2 - Authenticated (Author+) Regex Denial of Service
medium
The WP-Syntax plugin for WordPress is vulnerable to Regex Denial of Service in all versions up to, and including, 1.2. This is due to plugin not properly validating a regex before running it. This makes it possible for authenticated attackers, with Author-level access and above, to cause a limited denial of service bas...
- CVSS:
- 4.3
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 28, 2025
CVE-2024-13926 on NVD →
WP Syntax < 0.9.10 - Remote Code Execution
critical
WP-Syntax plugin 0.9.9 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function.
- CVSS:
- 9.8
- Affected:
- up to 0.9.9
- Fixed in:
- 0.9.10
- Disclosed:
- Apr 13, 2009
CVE-2009-2852 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database