Stored Cross-Site Scripting Vulnerability in WPML Plugin for WordPress
CVE-2025-3488
5.4MEDIUM
What is CVE-2025-3488?
The WPML plugin for WordPress has a security vulnerability that allows for Stored Cross-Site Scripting (XSS) through the wpml_language_switcher shortcode in versions 3.6.0 to 4.7.3. This arises from inadequate sanitization of user input and improper escaping of output, enabling authenticated attackers with contributor-level access or higher to insert malicious web scripts. These scripts can be executed when users access compromised pages, posing a significant risk to site integrity and user data security.
Affected Version(s)
WPML 3.6.0 <= 4.7.3