WP-GeSHi-Highlight <= 1.4.3 Authenticated (Author+) ReDoS

2025-03-20 00:00
Pierre Rudloff

Vulnerability Overview

The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages plugin for WordPress is vulnerable to Regex denial of service in all versions up to, and including, 1.4.3. This is due to the plugin not properly restricting regexes supplied to the wp_geshi_filter_replace_code() function. This makes it possible for authenticated attackers, with Author-level access and above, to cause a denial of service based on a bad regex.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C