Cross-site Scripting Vulnerability in CodeColorer by Dmytro Shteflyuk
CVE-2025-68012

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 January 2026

What is CVE-2025-68012?

A Cross-site Scripting (XSS) vulnerability exists in the CodeColorer plugin maintained by Dmytro Shteflyuk. This security flaw allows for stored XSS attacks, whereby an attacker can inject malicious scripts into web pages viewed by other users. This vulnerability impacts versions from n/a up to 0.10.1, enabling potential exploitation if these versions are utilized. Users of the affected versions should take immediate action to remediate this issue to safeguard their sites and user data from unauthorized access and malicious activities.

Affected Version(s)

CodeColorer 0 <= 0.10.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.