Description
WordPress Plugin Crayon Syntax Highlighter is prone to a remote file include vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Crayon Syntax Highlighter version 1.12.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.13 or latest
References
Related Vulnerabilities
WordPress Plugin Really Simple Share Cross-Site Request Forgery (2.9.9)
WordPress Plugin WpGenius Job Listing Cross-Site Scripting (1.0.2)
WordPress Plugin Elementor Website Builder Arbitrary File Upload (2.7.4)
WordPress Plugin Custom 404 Pro Cross-Site Scripting (3.2.7)
WordPress 4.9.x Arbitrary File Deletion Vulnerability (4.9 - 4.9.6)