Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alordiel Dropdown Multisite selector dropdown-multisite-selector allows Stored XSS.This issue affects Dropdown Multisite selector: from n/a through < 0.9.4.
Published: 2025-03-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper neutralization of user input during web page generation and permits a stored cross‑site scripting attack. An attacker can inject malicious JavaScript that later executes in the browsers of any user who views the affected page, enabling session hijack, defacement, or other client‑side compromises. The weakness is classified as CWE‑79 and is characterized by the injection of untrusted data that is subsequently rendered without adequate escaping.

Affected Systems

The issue affects the WordPress plugin alordiel Dropdown Multisite selector in all releases up to, but not including, version 0.9.4. The plugin is used to provide a dropdown selector for multisite WordPress installations.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly documented exploits. Likely exploitation would involve an attacker submitting malicious content through the plugin’s storage mechanism—most plausibly via the administrator interface or a public-facing form—so that the stored payload is later displayed to site visitors. While the attack vector is predictable, the low EPSS and absence from KEV reduce the immediacy of risk, though the potential impact on users remains significant.

Generated by OpenCVE AI on May 1, 2026 at 03:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the alordiel Dropdown Multisite selector plugin to version 0.9.4 or later
  • If an upgrade is not immediately feasible, remove the plugin from the WordPress installation to eliminate the stored‑XSS vector
  • Ensure that any remaining content stored by the plugin is sanitized or escaped according to WordPress best practices to prevent inadvertent injection

Generated by OpenCVE AI on May 1, 2026 at 03:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8570 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alordiel Dropdown Multisite selector allows Stored XSS. This issue affects Dropdown Multisite selector: from n/a through n/a.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alordiel Dropdown Multisite selector allows Stored XSS. This issue affects Dropdown Multisite selector: from n/a through n/a. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alordiel Dropdown Multisite selector dropdown-multisite-selector allows Stored XSS.This issue affects Dropdown Multisite selector: from n/a through < 0.9.4.
Title WordPress Dropdown Multisite selector < 0.9.4 - Cross Site Scripting (XSS) Vulnerability WordPress Dropdown Multisite selector plugin < 0.9.4 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 09:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alordiel Dropdown Multisite selector allows Stored XSS. This issue affects Dropdown Multisite selector: from n/a through n/a.
Title WordPress Dropdown Multisite selector < 0.9.4 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:05.068Z

Reserved: 2025-03-26T09:26:11.885Z

Link: CVE-2025-31090

cve-icon Vulnrichment

Updated: 2025-03-28T14:18:59.878Z

cve-icon NVD

Status : Deferred

Published: 2025-03-28T10:15:17.467

Modified: 2026-04-23T15:27:41.247

Link: CVE-2025-31090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T03:45:07Z

Weaknesses