Impact
The issue is a contributor‑level cross‑site scripting flaw that allows an attacker to inject arbitrary HTML or JavaScript into pages served by the WordPress Polylang plugin. Because the plugin treats user‑supplied data from contributors without proper encoding, a crafted string can be executed in the browser context of any visitor rendering the page. This flaw can lead to defacement, credential theft, or session hijacking as the script runs with the privileges of the viewing user. The weakness is classified under CWE‑79, representing insecure handling of user input in output contexts.
Affected Systems
WordPress sites that use the Polylang plugin version 3.8.9 or earlier. The plugin is distributed through the Chouby trademark and is commonly installed on multilingual WordPress deployments. No specific versions beyond 3.8.9 are affected; newer releases contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the vulnerability is publicly known with no exploitation metrics reported, so the EPSS score is unavailable. It is not yet listed in the CISA KEV catalog. Attackers typically need the ability to submit content or manipulate contributor input, so the impact requires a contributor or application level compromise. Once the malicious content is processed, any visitor to the compromised page will execute the injected script, enabling a wide range of malicious actions.
OpenCVE Enrichment