Cyber Posture

CVE-2025-23493

High

Published: 03 March 2025

Published
03 March 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0011 29.2th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moallemi Google Transliteration google-transliteration allows Reflected XSS.This issue affects Google Transliteration: from n/a through <= 1.7.2.

Security Summary

CVE-2025-23493 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the moallemi Google Transliteration WordPress plugin (google-transliteration). This issue affects all versions from n/a through 1.7.2 and was published on 2025-03-03.

The vulnerability has a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating it can be exploited remotely over the network by unauthenticated attackers with low attack complexity, though it requires user interaction. Attackers can trick users into interacting with maliciously crafted input reflected in web page generation, enabling arbitrary script execution in the victim's browser context and achieving low impacts on confidentiality, integrity, and availability with a changed scope.

The Patchstack advisory documents this vulnerability in their WordPress plugin database, providing details on the affected google-transliteration plugin version 1.7.2 Reflected XSS issue.

Details

CWE(s)
CWE-79

References