Syntax Highlighter Compress

Syntax Highlighter Compress has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Syntax Highlighter Compress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Abdulsamad Yusuf (0xVenus). Syntax Highlighter Compress is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.2.1.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Syntax Highlighter Compress vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2025-68859

Syntax Highlighter Compress <= 3.0.83.3 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv3.0.83.3

Syntax Highlighter Compress

agmorpheus

Author

agmorpheus

4.8(5)
96/100
Last Updated
2011-11-28 (15y ago)
Active Installs
80+
Downloads
24,408
Requires WP
2.6+
Requires PHP
0+
Tested up to
WP 3.2.1
Created
2010-04-24 (17y ago)

Syntax Highlighter ComPress is a simple WordPress plugin, that is based on the latest Alex Gorbatchev’s SyntaxHighlighter Script. Code and source text of different mark-up or programming languages can be highlighted in WordPress. There are other WordPress plugin based on the SyntaxHighlighter Script but these cause long page loading times and they are difficult to handle. The advantage of Syntax Highlighter ComPress is that only necessary brush files will be loaded dynamically. Another advantage is that your code can easily pasted into your posts, no need to replace all &#8216;<&#8216; with &#8216;<&#8216;. Supported mark-up or programming are: AppleScript, ActionScript3, Bash/shell, Coldfusion, C#, C++, CSS, Delphi, Diff, Erlang, Groovy, JavaScript, Java, JavaFX, Perl, PHP, Plain Text, Python, Ruby, Scala, SQL, Visual Basic and XML. The plugin is localized in English, German and Romanian.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C