CVE-2023-4893 describes a Server-Side Request Forgery (SSRF) vulnerability in the Crayon Syntax Highlighter plugin for WordPress, affecting versions up to and including 2.8.4. Authenticated attackers with contributor-level permissions or higher can exploit this flaw to force the web application to make requests to arbitrary internal or external locations, potentially querying or modifying sensitive internal service information. Rated as Medium severity (CVSS 5.4), this vulnerability has a low attack complexity and requires only low privileges, though it does not appear to be actively exploited, nor is there public exploit code or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.4CPE matchmatch criteria | cpe:2.3:a:aramk:crayon-syntax-highlighter:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.