WordPress Xili Language Plugin XSS Vulnerability

Summary
This host is running WordPress with Xili Language plugin and is prone to cross site scripting vulnerability.
Impact
Successful exploitation will allow remote attackers to insert arbitrary HTML and script code, which will be executed in a user's browser session in the context of an affected site. Impact Level: Application
Solution
Update to Xili Language Plugin version 2.8.5 or later, For updates refer to http://wordpress.org/extend/plugins/xili-language
Insight
The input passed via 'lang' parameter to index.php script is not properly validated.
Affected
WordPress Xili Language Plugin version 2.8.4.3 and prior
References