Impact
The WP Multilang plugin possesses a stored XSS flaw in every release up to 2.4.31. Improper sanitization of post content allows an attacker with Contributor‑level access to embed malicious scripts, which are rendered whenever any user views the affected page. The injected scripts run in the victim’s browser and can hijack sessions, deface content, or exfiltrate data, thereby harming the site’s confidentiality, integrity, and user experience.
Affected Systems
The vulnerability affects the WP Multilang – Translation and Multilingual Plugin released by magazine3, specifically all versions up to and including 2.4.31. Any WordPress site running these releases is susceptible.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and no EPSS value is available to gauge current exploitation likelihood. The flaw does not appear in the CISA KEV list. Attackers must first obtain authenticated Contributor or higher privileges to inject the payload, after which the malicious code executes in the browsers of all visitors to the edited post. Existing edits that contain untrusted input are ideal targets for exploitation.
OpenCVE Enrichment