PT-2026-33253 · WordPress · Codecolorer

Chawabhon Netisingha

·

Published

2026-04-16

·

Updated

2026-04-16

·

CVE-2026-4032

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CodeColorer versions prior to 0.10.2
Description The CodeColorer plugin for WordPress contains a Stored Cross-Site Scripting issue. This occurs due to insufficient input sanitization and output escaping within the class parameter of the 'cc' comment shortcode. Unauthenticated attackers can inject arbitrary web scripts into pages, which execute when a user accesses the affected page. This exploitation is possible if comments are enabled on the target post and guest comments are permitted.
Recommendations Update to a version later than 0.10.1.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4032

Affected Products

Codecolorer