WordPress Plugin Vulnerabilities

WP-Syntax <= 1.2 - Author+ Potential ReDoS

Description

The plugin does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby exploiting a catastrophic backtracking issue in the regular expression processing to cause a DoS.

Proof of Concept

Affects Plugins

No known fix

References

Miscellaneous

Original Researcher
Pierre Rudloff
Submitter
Pierre Rudloff
Verified
Yes

Timeline

Publicly Published
2025-03-28 (about 9 months ago)
Added
2025-03-28 (about 9 months ago)
Last Updated
2025-03-28 (about 9 months ago)

Other