Executive brief
The Easy Prism Syntax Highlighter plugin for WordPress, which is used to display formatted code snippets on websites, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into pages. When other users or administrators visit these pages, the scripts execute, potentially leading to unauthorized actions or data theft.
Technical details
The Easy Prism Syntax Highlighter plugin for WordPress (versions <= 1.0.2) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the shortcode() function. Specifically, the plugin concatenates the first positional attribute of the 'code' or 'c' shortcodes directly into the HTML class attribute of <pre> or <code> tags without using esc_attr(). An authenticated attacker with contributor-level permissions can exploit this to inject malicious JavaScript. The script executes in the context of any user's browser who views the affected page, which can lead to session hijacking or unauthorized administrative actions.
Affected products
- WordPress Easy Prism Syntax Highlighter up to, and including, 1.0.2
Timeline
- 2026-05-27: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/easy-prism-syntax-highlighter/trunk/PrismSyntaxHighlither.php
- https://plugins.trac.wordpress.org/browser/easy-prism-syntax-highlighter/trunk/PrismSyntaxHighlither.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/aa690c4d-15c4-43bc-b8f7-017b7741c5cd?source=cve