CVE-2024-13926: Connections-Pro Wp-Syntax

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby exploiting a catastrophic backtracking issue in the regular expression processing to cause a DoS.

Affected products

Published 2025-04-19. Last modified 2026-06-17.