Syntax Highlighter Compress
Syntax Highlighter Compress has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Syntax Highlighter Compress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Abdulsamad Yusuf (0xVenus). Syntax Highlighter Compress is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.2.1.
CVE-2025-68859Syntax Highlighter Compress <= 3.0.83.3 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Syntax Highlighter Compress
Author
agmorpheus
Syntax Highlighter ComPress is a simple WordPress plugin, that is based on the latest Alex Gorbatchev’s SyntaxHighlighter Script. Code and source text of different mark-up or programming languages can be highlighted in WordPress. There are other WordPress plugin based on the SyntaxHighlighter Script but these cause long page loading times and they are difficult to handle. The advantage of Syntax Highlighter ComPress is that only necessary brush files will be loaded dynamically. Another advantage is that your code can easily pasted into your posts, no need to replace all ‘<‘ with ‘<‘. Supported mark-up or programming are: AppleScript, ActionScript3, Bash/shell, Coldfusion, C#, C++, CSS, Delphi, Diff, Erlang, Groovy, JavaScript, Java, JavaFX, Perl, PHP, Plain Text, Python, Ruby, Scala, SQL, Visual Basic and XML. The plugin is localized in English, German and Romanian.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C