Stored Cross-Site Scripting Vulnerability in CodeColorer Plugin for WordPress
CVE-2026-4032

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 April 2026

What is CVE-2026-4032?

The CodeColorer plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'class' parameter of the 'cc' comment shortcode. This flaw allows unauthenticated attackers to inject malicious scripts that execute whenever a user visits an affected page. For exploitation, the target post must have comments enabled, and guest comments need to be permitted, potentially leading to unauthorized access or manipulation of web content.

Affected Version(s)

CodeColorer 0 <= 0.10.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chawabhon Netisingha
.