Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.1

CodeColorer plugin for WordPress allows attackers to inject malicious code

CVE-2026-4032
Summary

The CodeColorer WordPress plugin is at risk because attackers can inject malicious code into web pages. This could happen when a user views a page with a malicious comment. To stay safe, update the plugin to the latest version or remove it if you don't use it.

Original title
The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient in...
Original description
The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires comments to be enabled on the target post and guest comments to be allowed.
nvd CVSS3.1 6.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 16 Apr 2026 · Updated: 16 Apr 2026 · First seen: 16 Apr 2026