plugin

Xili Language Vulnerabilities

5 known security issues reported for the Xili Language WordPress plugin. Most recent disclosed Sep 22, 2025.

2 medium

Running Xili Language on your site? Check whether your installed version is affected.

Scan your site free

xili-language <= 2.21.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The xili-language plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.21.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 2.21.3
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-58654 on NVD →

xili-language <= 2.21.2 - Reflected Cross-Site Scripting

medium

The xili-language plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.21.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 2.21.2
Fixed in:
2.21.3
Disclosed:
Apr 1, 2025

CVE-2025-31085 on NVD →

xili-language [xili-language] < 2.21.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language allows Reflected XSS. This issue affects xili-language: from n/a through 2.21.2.

Affected:
up to 2.21.3
Fixed in:
2.21.3
Disclosed:
Apr 1, 2025

CVE-2025-31085 on NVD →

xili-language [xili-language] < 2.8.6

unknown

This plugin is prone to a cross site scripting vulnerability in index.php lang parameter. Update the plugin.

Affected:
up to 2.8.6
Fixed in:
2.8.6
Disclosed:
May 15, 2015

xili-language [xili-language] < 2.8.6

unknown

The xili-language WordPress plugin was affected by an index.php lang Parameter XSS security vulnerability.

Affected:
up to 2.8.6
Fixed in:
2.8.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database