plugin

Google Language Translator Vulnerabilities

26 known security issues reported for the Google Language Translator WordPress plugin. Most recent disclosed Dec 9, 2024.

2 high 11 medium

Running Google Language Translator on your site? Check whether your installed version is affected.

Scan your site free

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.20

unknown

[en] Missing Authorization vulnerability in Translate AI Multilingual Solutions Google Language Translator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Language Translator: from n/a through 6.0.19.

Affected:
up to 6.0.20
Fixed in:
6.0.20
Disclosed:
Dec 9, 2024

CVE-2023-50375 on NVD →

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.10

unknown

[en] The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Oct 16, 2024

CVE-2021-4452 on NVD →

Google Language Translator <= 6.0.19 - Missing Authorization via admin notifications

medium

The Google Language Translator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple admin notification functions in versions up to, and including, 6.0.19. This makes it possible for unauthenticated attackers to set admin notifications to an ignored status...

CVSS:
5.3
Affected:
up to 6.0.19
Fixed in:
6.0.20
Disclosed:
Dec 13, 2023

CVE-2023-50375 on NVD →

Google Language Translator < 6.0.20 - Missing Authorization to Notice Dismissal

medium

The Translate WordPress – Google Language Translator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notice_ignore() function in all versions up to 6.0.20 (exclusive). This makes it possible for unauthenticated attackers to dismiss admin notices.

CVSS:
5.3
Affected:
up to 6.0.20
Fixed in:
6.0.20
Disclosed:
Dec 8, 2023

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.20

unknown

The Translate WordPress – Google Language Translator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notice_ignore() function in all versions up to 6.0.20 (exclusive). This makes it possible for unauthenticated attackers to dismiss admin notices.

Affected:
up to 6.0.20
Fixed in:
6.0.20
Disclosed:
Dec 8, 2023

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.14

unknown

[en] The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admi...

Affected:
up to 6.0.14
Fixed in:
6.0.14
Disclosed:
Mar 28, 2022

CVE-2022-0770 on NVD →

Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 - Missing Authorization to Sensitive Information Disclosure

high

The Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 WordPress plugins do not have proper capabilities checks in the /wp-content/plugins/gtranslate/url_addon/gtranslate.php file which writes debug data such as user's cookies in a publicly accessible file when t...

CVSS:
8.8
Affected:
up to 6.0.13
Fixed in:
6.0.14
Disclosed:
Mar 7, 2022

CVE-2022-0770 on NVD →

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.12

unknown

[en] The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 6.0.12
Fixed in:
6.0.12
Disclosed:
Nov 8, 2021

CVE-2021-24594 on NVD →

Translate WordPress - Google Language Translator <= 6.0.11 - Admin+ Stored Cross-Site Scripting

medium

The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
4.8
Affected:
up to 6.0.12
Fixed in:
6.0.12
Disclosed:
Oct 5, 2021

CVE-2021-24594 on NVD →

Translate WordPress - Google Language Translator < 6.0.12 - Admin+ Stored Cross-Site Scripting

medium
Affected:
up to 6.0.12
Fixed in:
6.0.12
Disclosed:
Oct 5, 2021

CVE-2021-24594 on NVD →

Google Language Translator <= 6.0.9 - Reflected Cross-Site Scripting

high

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
7.1
Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Jul 21, 2021

CVE-2021-4452 on NVD →

Google Language Translator < 6.0.10 - Authenticated (author+) Cross-Site Scripting (XSS)

medium
Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Jul 21, 2021

Google Language Translator < 6.0.10 - Authenticated Cross-Site Scripting (XSS)

medium
Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Jul 21, 2021

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.10

unknown

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Jul 21, 2021

Google Language Translator <= 6.0.9 - Authenticated Cross-Site Scripting

medium

The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Scripting via the glt shortcode in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers at the Author level to inject arbitrary web scripts in pa...

CVSS:
6.4
Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Jul 20, 2021

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.10

unknown

The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Scripting via the glt shortcode in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers at the Author level to inject arbitrary web scripts in pa...

Affected:
up to 6.0.10
Fixed in:
6.0.10
Disclosed:
Jul 20, 2021

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 5.0.06

unknown

[en] The google-language-translator plugin before 5.0.06 for WordPress has XSS.

Affected:
up to 5.0.06
Fixed in:
5.0.06
Disclosed:
Aug 13, 2019

CVE-2016-10870 on NVD →

Google Language Translator <= 5.0.05 - XSS

medium
Affected:
up to 5.0.06
Fixed in:
5.0.06
Disclosed:
Apr 19, 2016

CVE-2016-10870 on NVD →

Google Language Translator <= 5.0.05 - Cross-Site Scripting

medium

The google-language-translator plugin before 5.0.06 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 5.0.06
Fixed in:
5.0.06
Disclosed:
Apr 18, 2016

CVE-2016-10870 on NVD →

Google Language Translator <= 4.0.9 - Authenticated Stored Cross-Site Scripting

medium

The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.9 via 'the googlelanguagetranslator_flags_order' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 5.0.0
Fixed in:
5.0.0
Disclosed:
Aug 13, 2015

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 5.0.0

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Vulnerable parameter is "googlelanguagetranslator_flags_order". Upgrade this plugin.

Affected:
up to 5.0.0
Fixed in:
5.0.0
Disclosed:
Aug 13, 2015

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 5.0.0

unknown

The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.9 via 'the googlelanguagetranslator_flags_order' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web script...

Affected:
up to 5.0.0
Fixed in:
5.0.0
Disclosed:
Aug 13, 2015

Google Language Translator < 5.0.0 - Authenticated Cross-Site Scripting (XSS)

medium
Affected:
up to 5.0.0
Fixed in:
5.0.0
Disclosed:
Aug 13, 2015

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.10

unknown

The plugin was vulnerable to Authenticated Cross-Site Scripting (XSS) allowing a user with Author role to execute malicious JavaScript via the glt shortcode.

Affected:
up to 6.0.10
Fixed in:
6.0.10

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.10

unknown

The plugin was vulnerable to Authenticated Cross-Site Scripting (XSS) only affecting older web browsers such as Internet Explorer &lt;= 9.

Affected:
up to 6.0.10
Fixed in:
6.0.10

Translate WordPress &#8211; Google Language Translator [google-language-translator] < 5.0.0

unknown

The Translate WordPress &ndash; Google Language Translator WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.0.0
Fixed in:
5.0.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database