CVE-2025-46239: WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability
Published Apr 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from n/a through <= 3.4.
Affected Software
3 affected components
Jeff Starr Theme Switcha<=3.4
WordPress Theme Switcha<=3.4
Plugin-planet Theme Switcha Wordpress<3.4.1
Remediation
Information
Update the WordPress Theme Switcha plugin to the latest available version (at least 3.4.1).
Event History
Apr 22, 2025
CVE Published
via MITRE·09:53 AM
Data Sourced
via MITRE·09:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46239?
CVE-2025-46239 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-46239?
To fix CVE-2025-46239, update the Theme Switcha plugin to version 3.5 or later.
3
What software is affected by CVE-2025-46239?
CVE-2025-46239 affects Theme Switcha versions up to and including 3.4.
4
Can CVE-2025-46239 be exploited remotely?
Yes, CVE-2025-46239 can be exploited remotely by attackers who can inject malicious scripts.
5
What are the potential impacts of CVE-2025-46239?
The potential impacts of CVE-2025-46239 include unauthorized data access and session hijacking due to executed malicious scripts.