SyntaxHighlighter Evolved
SyntaxHighlighter Evolved has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).
Every one of the 3 issues recorded for SyntaxHighlighter Evolved has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. SyntaxHighlighter Evolved is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
SyntaxHighlighter Evolved < 3.5.1 - Stored Cross-Site Scripting
Read the full analysisVulnerability Records

SyntaxHighlighter Evolved
Author
Alex Mills
Now with support for the new block editor in WordPress 5.0! SyntaxHighlighter Evolved allows you to easily post syntax-highlighted code to your site without losing its formatting or making any manual changes. It uses the SyntaxHighlighter JavaScript package by Alex Gorbatchev. For a live demo, see this plugin’s homepage. For a list of supported languages (most widely used languages are supported), see the WordPress.com support document. Development of this plugin is on GitHub. Translation of the plugin into different languages is on the translation page. As seen on WordPress.com.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C