{"id":"CVE-2019-12934","details":"An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.","modified":"2026-08-27T08:15:15.959871Z","published":"2019-07-20T00:15:11.477Z","references":[{"type":"WEB","url":"https://wordpress.org/plugins/wp-code-highlightjs/#developers"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/109331"},{"type":"EVIDENCE","url":"https://zeroauth.ltd/blog/2019/07/17/cve-2019-12934-wp-code-highlightjs-wordpress-plugin-csrf-leads-to-blog-wide-injected-script-html/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/owent/WP-Code-Highlight.js","events":[{"introduced":"0"},{"last_affected":"1944e1dd097093c2ca6080ff8089e46ba287064f"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:wp-code-highlightjs_project:wp-code-highlightjs:*:*:*:*:*:wordpress:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.6.2"}]}}],"versions":["0.6.2","0.6.1","0.6.0","0.5.17","0.5.16","0.5.15","0.5.13","0.5.12","0.5.11","0.5.9","0.5.0","0.4.4","0.4.3","0.3.7","0.3.0","0.1.8","v0.1.2","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12934.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}