Input validation vulnerability in Urvanov Syntax Highlighter 2.8.33

The Urvanov Syntax Highlighter plugin for WordPress has a security issue that affects versions up to 2.8.33. This means that unauthenticated attackers can use a forged link to perform certain actions, like saving, submitting, duplicating, and deleting syntax highlighting blocks, without the site administrator’s knowledge. This is because the plugin is missing or incorrect nonce validation on the init_ajax function.

Detected in:

Urvanov Syntax Highlighter fixed vulnerable versions: >= * <= 2.8.33

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.