CodeColorer

CodeColorer has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).

Every one of the 3 issues recorded for CodeColorer has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. CodeColorer is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all CodeColorer vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2025-68012

CodeColorer <= 0.10.1 - Unauthenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
CodeColorer banner
Latestv0.12.0
4.9(11)
98/100
Last Updated
2026-08-15 (29d ago)
Active Installs
1,000+
Downloads
127,538
Requires WP
4.0+
Requires PHP
7.0+
Tested up to
WP 7.1
Created
2007-04-09 (20y ago)

CodeColorer lets you insert syntax-highlighted code snippets into posts, comments, and feeds. CodeColorer currently bundles GeSHi 1.0.9.0 from the upstream 1.0.x line, with a small set of project-local maintenance patches for current PHP and WordPress compatibility. Plugin based on GeSHi library, which supports most languages. CodeColorer has various nice features: syntax highlighting in RSS feeds syntax highlighting of a single line of code (inline) syntax highlighting of code in comments line numbers automatic links to the documentation inserting code block intelligent scroll detection (short code would have a short block, for a long one the block height would be fixed and a scrollbar would appear) predefined color themes (Slush & Poppies, Blackboard, Dawn, Mac Classic, Twitlight, Vibrant Ink, Railscasts, Solarized Light, Solarized Dark) syntax colors customization in CSS file code protect from mangling by WordPress (for example, quotes, double-dashes, and others would look just right as you entered) Support If you have any suggestions, found a bug, wanted to contribute a translation to your language, or just wanted to say “thank you”, feel free to email me kpumuk@kpumuk.info. I will try my best to answer you. If you want to contribute your code, see the Development section under the Other Notes tab. Supported languages Here is the list of languages supported by CodeColorer: 4cs, 6502acme, 6502kickass, 6502tasm, 68000devpac, abap, actionscript, actionscript3, ada, aimms, algol68, apache, applescript, apt_sources, arm, asm, asp, asymptote, autoconf, autohotkey, autoit, avisynth, awk, bascomavr, bash, basic4gl, batch, bf, biblatex, bibtex, blitzbasic, bnf, boo, c, c_loadrunner, c_mac, c_winapi, caddcl, cadlisp, ceylon, cfdg, cfm, chaiscript, chapel, cil, clojure, cmake, cobol, coffeescript, cpp-qt, cpp-winapi, cpp, csharp, css, cuesheet, d, dart, dcl, dcpu16, dcs, delphi, diff, div, dos, dot, e, ecmascript, eiffel, email, epc, erlang, euphoria, ezt, f1, falcon, fo, fortran, freebasic, freeswitch, fsharp, gambas, gdb, genero, genie, gettext, glsl, gml, gnuplot, go, groovy, gwbasic, haskell, haxe, hicest, hq9plus, html4strict, icon, idl, ini, inno, intercal, io, ispfpanel, j, java, java5, javascript, jcl, jquery, julia, kixtart, klonec, klonecpp, kotlin, latex, lb, ldif, lisp, llvm, locobasic, logtalk, lolcode, lotusformulas, lotusscript, lscript, lsl2, lua, m68k, magiksf, make, mapbasic, mathematica, matlab, mercury, metapost, mirc, mk-61, mmix, modula2, modula3, mpasm, mxml, mysql, nagios, netrexx, newlisp, nginx, nimrod, nsis, oberon2, objc, objeck, ocaml-brief, ocaml, octave, oobas, oorexx, oracle11, oracle8, oxygene, oz, parasail, parigp, pascal, pcre, per, perl, perl6, pf, phix, php-brief, php, pic16, pike, pixelbender, pli, plsql, postgresql, postscript, povray, powerbuilder, powershell, proftpd, progress, prolog, properties, providex, purebasic, pycon, pys60, python, q, qbasic, qml, racket, rails, rbs, rebol, reg, rexx, robots, rpmspec, rsplus, ruby, rust, sas, sass, scala, scheme, scilab, scl, sdlbasic, smalltalk, smarty, spark, sparql, sql, standardml, stonescript, swift, systemverilog, tcl, tclegg, teraterm, texgraph, text, thinbasic, tsql, twig, typoscript, unicon, upc, urbi, uscript, vala, vb, vbnet, vbscript, vedit, verilog, vhdl, vim, visualfoxpro, visualprolog, whitespace, whois, winbatch, xbasic, xml, xojo, xorg_conf, xpp, xyscript, yaml, z80, zxbasic. Development Sources of this plugin are available both in SVN and Git: WordPress SVN repository GitHub The GitHub repository includes local contributor tooling based on mise, Composer, pnpm, and wp-env. A typical setup is: mise install mise run bootstrap mise run test mise run wp-start Feel free to check them out, make your changes and send me patches or pull requests. Promise, I will apply every patch (of course, if they add a value to the product). Email for patches, suggestions, or bug reports: kpumuk@kpumuk.info. If you’re interested in translating CodeColorer to your language, please check out the translation page for the plugin. Customization Syntax coloring is highly customizable: you could change the color scheme for all languages or a specific language. You could find CodeColorer CSS in wp-content/plugins/codecolorer/codecolorer.css file. To change colors for all languages edit lines below Color scheme section. There is a simple mapping between TextMate color themes and CodeColorer ones: /* "Slush & Poppies" color scheme (default) */ .codecolorer-container, .codecolorer { color: #000000; background-color: #F1F1F1; } /* Comment */ .codecolorer .co0, .codecolorer .co1, .codecolorer .co2, .codecolorer .co3, .codecolorer .co4, .codecolorer .coMULTI { color: #406040; font-style: italic; } /* Constant */ .codecolorer .nu0, .codecolorer .re3 { color: #0080A0; } /* String */ .codecolorer .st0, .codecolorer .st_h, .codecolorer .es0, .codecolorer .es1 { color: #C03030; } /* Entity */ .codecolorer .me1, .codecolorer .me2 { color: #0080FF; } /* Keyword */ .codecolorer .kw1, .codecolorer .kw2, .codecolorer .sy1 { color: #2060A0; } /* Storage */ .codecolorer .kw3, .codecolorer .kw4, .codecolorer .kw5, .codecolorer .re2 { color: #008080; } /* Variable */ .codecolorer .re0, .codecolorer .re1 { color: #A08000; } /* Global color */ .codecolorer .br0, .codecolorer .sy0 { color: #000000; } Check the codecolorer.css file to get more examples.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C