Stored Cross-Site Scripting Vulnerability in CodeColorer Plugin for WordPress
CVE-2026-4032
6.1MEDIUM
What is CVE-2026-4032?
The CodeColorer plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'class' parameter of the 'cc' comment shortcode. This flaw allows unauthenticated attackers to inject malicious scripts that execute whenever a user visits an affected page. For exploitation, the target post must have comments enabled, and guest comments need to be permitted, potentially leading to unauthorized access or manipulation of web content.
Affected Version(s)
CodeColorer 0 <= 0.10.1