WORDFENCE-eff47e59-9a2c-424f-b138-47fcf554c06b
critical
📛 Threat Title
Crayon Syntax Highlighter Plugin <= 1.13 - Remote File Inclusion
Description
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.13 via the crayon_is_php_file function. This allows unauthenticated attackers to include remote files on the server, resulting in code execution. Affected software — plugin: Crayon Syntax Highlighter (affected: *-1.13). CVSS 9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: Crayon Syntax HighlighterWordfence
Update to version 1.14, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.