Impact
The defect in WP Multilang allows an unauthenticated attacker to inject arbitrary JavaScript into responses served by the site. The injected script runs in the context of the victim’s browser, enabling execution of arbitrary client‑side code, theft of session cookies, and manipulation or defacement of the page. Because no authentication is required to exploit the flaw, the risk applies to any user accessing the site, potentially leading to loss of confidentiality, integrity, or availability of the affected WordPress installation.
Affected Systems
Magazine3’s WP Multilang plugin, versions 2.4.31 and earlier, are vulnerable. Any WordPress site that has installed these plugin versions is impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is not available, so the current likelihood of exploitation is unknown, and the flaw is not listed in the CISA KEV catalog, suggesting no publicly confirmed exploits yet. The attack vector is likely via unauthenticated input to the plugin’s front‑end, making the flaw exploitable by any visitor to the site.
OpenCVE Enrichment