CVE-2025-3488: WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode
The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmllanguageswitcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What versions of the WPML plugin are affected by CVE-2025-3488?
CVE-2025-3488 affects WPML plugin versions 3.6.0 to 4.7.3.
What type of vulnerability is CVE-2025-3488?
CVE-2025-3488 is a Stored Cross-Site Scripting vulnerability.
How do I fix CVE-2025-3488?
To fix CVE-2025-3488, update the WPML plugin to a version later than 4.7.3.
What is the impact of CVE-2025-3488 on users?
CVE-2025-3488 allows authenticated attackers to inject malicious scripts that can be executed by users.
What is the cause of the CVE-2025-3488 vulnerability?
CVE-2025-3488 is caused by insufficient input sanitization and output escaping on user-supplied attributes in the wpml_language_switcher shortcode.