Description
WordPress Plugin Crayon Syntax Highlighter is prone to a remote file include vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Crayon Syntax Highlighter version 1.12.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.13 or latest
References
Related Vulnerabilities
WordPress Plugin Ad Blocker Notify Lite Cross-Site Scripting (2.4.0)
WordPress Plugin Comment Rating 'path' Parameter Cross-Site Scripting (2.9.20)
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.8)
WordPress Plugin Clever Addons for Elementor Multiple Cross-Site Scripting Vulnerabilities (2.0.15)