Cross-Site Scripting Vulnerability in Dreamwinner Easy Language Switcher
CVE-2024-56029

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 January 2025

What is CVE-2024-56029?

The vulnerability in Dreamwinner's Easy Language Switcher results from improper neutralization of input during web page generation, leading to a reflected cross-site scripting (XSS) issue. This allows attackers to inject malicious scripts into web pages viewed by users, potentially enabling unauthorized actions or data theft. The vulnerability impacts versions from n/a up to 1.0 of Easy Language Switcher, emphasizing the need for users to ensure their applications are updated and secured against such threats.

Affected Version(s)

Easy Language Switcher <= 1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)
.