Impact
An improper neutralization of user input in the CodeColorer WordPress plugin allows attackers to store and execute malicious JavaScript in a victim’s browser. The vulnerability, identified as CWE‑79, will only be triggered when the stored data is served by the plugin, leading to potential script execution in the context of authenticated users.
Affected Systems
The vulnerability affects the CodeColorer plugin developed by Dmytro Shteflyuk, all releases from the first version through and including version 0.10.1. These versions are distributed as WordPress plugins and are used in site editors that accept user‐generated content.
Risk and Exploitability
The CVSS score of 7.1 indicates a high level of impact with a moderate exploitation difficulty. The EPSS score of less than 1% suggests that current evidence of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because stored XSS can compromise any authenticated user’s session, site administrators should treat this as a critical security concern and mitigate it before further exploitation can be proven.
OpenCVE Enrichment