Junglewise Threat Intelligence

CVE-2026-12108: LOOS Web Studio Highlighting Code Block Stored XSS in admin settings

CVE-2026-12108 · Severity: medium · CVSS 4.4 · Published 2026-07-10

Executive brief

The Highlighting Code Block plugin for WordPress, which is used to display formatted code snippets on websites, contains a security flaw in its administrative settings. This vulnerability allows an authorized administrator to save malicious scripts into the site's configuration. These scripts will then execute in the browsers of other users who visit the affected pages, potentially leading to unauthorized actions or data theft. This issue primarily impacts WordPress multi-site environments or specific configurations where standard security restrictions on HTML content have been relaxed.

Technical details

The Highlighting Code Block plugin for WordPress (versions <= 2.2.0) is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of input and escaping of output within the plugin's administrative settings. An authenticated attacker with administrator-level privileges can inject arbitrary JavaScript into the database. This script executes when a user visits a page where the malicious setting is rendered. The vulnerability is specifically exploitable in WordPress multi-site installations or single-site installations where the 'unfiltered_html' capability has been disabled for administrators. The issue was addressed in versions following 2.2.0.

Affected products

  • LOOS Web Studio Highlighting Code Block up to, and including, 2.2.0

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References