Cross-Site Scripting Vulnerability in Webilop User Language Switch Plugin
CVE-2025-49064
7.1HIGH
What is CVE-2025-49064?
The Webilop User Language Switch plugin for WordPress has a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation. This flaw allows attackers to execute arbitrary JavaScript code through reflected XSS, potentially compromising user data and leading to unauthorized actions. The affected versions range from n/a up to and including 1.6.10, making it imperative for users to evaluate their installations and apply suitable safeguards against exploitation.
Affected Version(s)
User Language Switch <= 1.6.10