Description
WordPress Plugin Crayon Syntax Highlighter is prone to a remote file include vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Crayon Syntax Highlighter version 1.12.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.13 or latest
References
Related Vulnerabilities
Joomla! Core 1.5.12 Arbitrary File Upload (1.5.12)
Apache HTTP Server Incorrect Calculation of Buffer Size Vulnerability (CVE-2004-0747)
WordPress Plugin Ooorl Cross-Site Scripting (1.0.0)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-43952)
WordPress Plugin Thrive Themes Builder Security Bypass (2.2.3)