Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved syntaxhighlighter allows DOM-Based XSS.This issue affects SyntaxHighlighter Evolved: from n/a through <= 3.7.1.
Published: 2025-03-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject arbitrary HTML or JavaScript into web pages served by the SyntaxHighlighter Evolved plugin. Because the plugin fails to properly neutralize user‑supplied input when generating the page, the injected code runs in the victim’s browser, potentially compromising their session data, executing malware, or performing phishing attacks. This weakness is classified as CWE‑79 and elevates the integrity risk for any site relying on the plugin.

Affected Systems

The vulnerability affects versions of the SyntaxHighlighter Evolved plugin developed by Alex Mills that are version 3.7.1 or older. All releases from the earliest available through <=3.7.1 are impacted. Users running any of these versions of the plugin on their WordPress sites are at risk.

Risk and Exploitability

The CVSS core score of 6.5 indicates a medium to high severity, while the EPSS score of <1% shows that the likelihood of public exploitation is currently low. The plugin is not listed in the CISA KEV catalog. An attacker could exploit this by providing malicious content via the plugin’s configuration or by targeting users who view content rendered by the plugin, triggering the DOM‑based XSS when the page loads. As the vulnerability exists in the web‑accessible component, no special access is required beyond ability to view or input data into the plugin.

Generated by OpenCVE AI on May 1, 2026 at 03:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update SyntaxHighlighter Evolved to version 3.8 or newer to apply the vendor patch
  • Disable or remove the plugin if it is not required for site functionality
  • Implement or enforce input validation and output sanitization for any data processed by the plugin to prevent injected scripts

Generated by OpenCVE AI on May 1, 2026 at 03:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8308 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved allows DOM-Based XSS. This issue affects SyntaxHighlighter Evolved: from n/a through 3.7.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved allows DOM-Based XSS. This issue affects SyntaxHighlighter Evolved: from n/a through 3.7.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved syntaxhighlighter allows DOM-Based XSS.This issue affects SyntaxHighlighter Evolved: from n/a through <= 3.7.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 27 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved allows DOM-Based XSS. This issue affects SyntaxHighlighter Evolved: from n/a through 3.7.1.
Title WordPress SyntaxHighlighter Evolved plugin <= 3.7.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:00.012Z

Reserved: 2025-03-26T09:21:38.617Z

Link: CVE-2025-30903

cve-icon Vulnrichment

Updated: 2025-03-27T14:40:34.393Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:51.340

Modified: 2026-04-23T15:27:17.750

Link: CVE-2025-30903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T03:45:07Z

Weaknesses