Cross-site Scripting Vulnerability in Saiem Khan Image Switcher Plugin for WordPress
CVE-2025-23939
6.5MEDIUM
What is CVE-2025-23939?
The Saiem Khan Image Switcher plugin is susceptible to a stored Cross-site Scripting (XSS) vulnerability that occurs due to improper neutralization of input during web page generation. If an attacker successfully exploits this vulnerability, they could inject malicious scripts into the content that gets served on the website. This could lead to unauthorized actions taking place on behalf of legitimate users or the exposure of sensitive information.
Affected Version(s)
Image Switcher <= 1.1