CVE-2024-13926: WP-Syntax <= 1.2 - Author+ Potential ReDoS
Published Apr 19, 2025
·Updated
The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby exploiting a catastrophic backtracking issue in the regular expression processing to cause a DoS.
Affected Software
2 affected components
WP-Syntax WP-Syntax<=1.2
Connections-pro Wp-syntax Wordpress<=1.2
Event History
Apr 19, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-13926?
CVE-2024-13926 is classified as a denial of service (DoS) vulnerability.
2
How do I fix CVE-2024-13926?
To address CVE-2024-13926, update the WP-Syntax plugin to a version later than 1.2.
3
What versions of WP-Syntax are affected by CVE-2024-13926?
WP-Syntax versions up to and including 1.2 are affected by CVE-2024-13926.
4
What type of attack does CVE-2024-13926 enable?
CVE-2024-13926 enables an attacker to exploit a catastrophic backtracking issue for a denial of service attack.
5
What can happen if CVE-2024-13926 is exploited?
If CVE-2024-13926 is exploited, it can lead to service disruption due to excessive resource consumption.