Dropdown multisite selector
Dropdown multisite selector has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Dropdown multisite selector has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Dropdown multisite selector is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-31090Dropdown Multisite selector < 0.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Dropdown multisite selector
Author
alordiel
With this plugin you can create fully configurable dropdown field which select options would work as links and will redirect the user to the selected one. It was originally built for multisite for faster navigation between each sub-site, but currently it also supports custom links as options from the dropdown. There are three options: manually configure the number of the options from the dropdown element – pick up a name of your option and the relevant url where the user will be redirected after choosing it; get any list of all sites from WordPress Multisite network – this one picks the names of all your sites that are in the multisite network and adds them to the select element; get the same list as previous one but only with the site where the current logged-in user is registered; You can manage: Your label for the name of the select option or leave it without label Your first select option (‘Select branch’, ‘Select country’, ‘Choose Side’) Sorting of your custom list (alphabetic sorting + reverse sorting (your last entries will become first in the dropdown)) Once you have saved your settings you can see the result using this shortcode [dms] or use the widget. Shortcodes [dms] – Using this shortcode will generate the same dropdown as the one you have configured in the admin settings panel. [dms_manual name=”” placeholder=”” target=”” options=””] – Use this one your own dropdown that has nothing to do with the settings you have set. The arguments of this shortcode are: * name – the label of the select option (leave empty for no label) * placeholder – the first option that is shown in the select menu (like: “– Select –“) * target – could be “default” or “blank”. This is the target of the link – “blank” is to be open in new window * options – name-link pairs, should be placed as : “url1|name1, url2|name2, url3|name3” An example: [dms_manual name=”Label” placeholder=”–Select–” target=”blank” options=”Trusted search engine|https://duckduckgo.com, Tracking search engine|https://google.bg”] If you would more functionality, please contact me to check if I can implement it. Also thanks to everyone giving me hints how to improve this plugin. Filters in the code Here are some filters that you can use to modify the results from the code: * dms_sites_arguments – to control the attributes used in the function get_sites() when ‘Show all sites in the WMN’ option is selected. * dms_multisite_pairs – filter the results returned from get_sites(). * dms_users_sites – control the sites when ‘Show only the sites where the user is registered’ option is selected.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C