VYPR
High severity7.1NVD Advisory· Published Mar 3, 2025· Updated Apr 23, 2026

CVE-2025-23619

CVE-2025-23619

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Catch Duplicate Switcher catch-duplicate-switcher allows Reflected XSS.This issue affects Catch Duplicate Switcher: from n/a through <= 2.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in Catch Duplicate Switcher WordPress plugin allows attackers to inject malicious scripts via crafted requests.

The Catch Duplicate Switcher plugin for WordPress versions up to and including 2.0 suffers from a reflected cross-site scripting (XSS) vulnerability. The issue stems from improper neutralization of user-supplied input during web page generation, enabling attackers to inject arbitrary HTML and JavaScript into pages.

Exploitation does not require authentication but does require user interaction. An attacker can craft a malicious link containing the XSS payload and trick a privileged user (such as an administrator) into clicking it. The payload is reflected back and executed in the context of the victim's browser session.

Successful exploitation allows an attacker to perform actions such as redirecting visitors to malicious sites, injecting advertisements, or stealing sensitive information. The vulnerability is rated with a CVSS v3 score of 7.1 (High) and is considered likely to be exploited in mass campaigns targeting WordPress sites.

Users are strongly advised to update the plugin to a patched version if available. For immediate protection, Patchstack offers a virtual mitigation rule that blocks attacks until an official patch can be applied and tested [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.