Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded theme-switcher-reloaded allows Reflected XSS.This issue affects Theme Switcher Reloaded: from n/a through <= 1.1.
Published: 2025-08-28
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of user input, allowing a reflected Cross‑Site Scripting (XSS) vector. An attacker can supply malicious script payloads that are executed in the victim’s browser when the forged request reaches the plugin. This can lead to data theft, session hijacking, defacement of the site, or the execution of arbitrary JavaScript in the context of the site’s users.

Affected Systems

The issue affects the undoIT Theme Switcher Reloaded WordPress plugin, versions from n/a through the 1.1 release. Any WordPress site that has installed a vulnerable version of this theme‑switcher plugin is at risk unless the plugin is updated or removed.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score of less than 1% signals that active exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely compromised in the wild yet. Based on the description, the likely attack vector is a reflected XSS through crafted requests that the plugin fails to sanitize before rendering. The attack requires an attacker to supply a malicious query parameter or form input and persuade or trick a user to visit the crafted URL, which is typically feasible via phishing or compromised external content.

Generated by OpenCVE AI on April 30, 2026 at 07:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Theme Switcher Reloaded plugin to the latest release that contains the XSS fix.
  • If no patch is available, permanently remove or deactivate the plugin to eliminate the reflection surface.
  • Implement a strict content security policy that restricts inline script execution and limits script sources to trusted domains to mitigate potential XSS exploitation.

Generated by OpenCVE AI on April 30, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26002 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded allows Reflected XSS. This issue affects Theme Switcher Reloaded: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded allows Reflected XSS. This issue affects Theme Switcher Reloaded: from n/a through 1.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded theme-switcher-reloaded allows Reflected XSS.This issue affects Theme Switcher Reloaded: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 28 Aug 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 28 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded allows Reflected XSS. This issue affects Theme Switcher Reloaded: from n/a through 1.1.
Title WordPress Theme Switcher Reloaded Plugin <= 1.1 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:21.475Z

Reserved: 2025-06-27T10:28:03.499Z

Link: CVE-2025-53223

cve-icon Vulnrichment

Updated: 2025-08-28T13:29:48.880Z

cve-icon NVD

Status : Deferred

Published: 2025-08-28T13:16:01.343

Modified: 2026-04-23T15:32:19.203

Link: CVE-2025-53223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T07:45:26Z

Weaknesses