{ "schema_version": "1.4.0", "id": "GHSA-j6jm-3g52-98hf", "modified": "2022-05-24T16:50:47Z", "published": "2022-05-24T16:50:47Z", "aliases": [ "CVE-2019-12934" ], "details": "An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12934" }, { "type": "WEB", "url": "https://wordpress.org/plugins/wp-code-highlightjs/#developers" }, { "type": "WEB", "url": "https://zeroauth.ltd/blog/2019/07/17/cve-2019-12934-wp-code-highlightjs-wordpress-plugin-csrf-leads-to-blog-wide-injected-script-html" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/109331" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-07-20T00:15:00Z" } }