Translate WordPress – Google Language Translator [google-language-translator] < 6.0.20
unknown
[en] Missing Authorization vulnerability in Translate AI Multilingual Solutions Google Language Translator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Language Translator: from n/a through 6.0.19.
- Affected:
- up to 6.0.20
- Fixed in:
- 6.0.20
- Disclosed:
- Dec 9, 2024
CVE-2023-50375 on NVD →
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.10
unknown
[en] The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Oct 16, 2024
CVE-2021-4452 on NVD →
Google Language Translator <= 6.0.19 - Missing Authorization via admin notifications
medium
The Google Language Translator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple admin notification functions in versions up to, and including, 6.0.19. This makes it possible for unauthenticated attackers to set admin notifications to an ignored status...
- CVSS:
- 5.3
- Affected:
- up to 6.0.19
- Fixed in:
- 6.0.20
- Disclosed:
- Dec 13, 2023
CVE-2023-50375 on NVD →
Google Language Translator < 6.0.20 - Missing Authorization to Notice Dismissal
medium
The Translate WordPress – Google Language Translator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notice_ignore() function in all versions up to 6.0.20 (exclusive). This makes it possible for unauthenticated attackers to dismiss admin notices.
- CVSS:
- 5.3
- Affected:
- up to 6.0.20
- Fixed in:
- 6.0.20
- Disclosed:
- Dec 8, 2023
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.20
unknown
The Translate WordPress – Google Language Translator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notice_ignore() function in all versions up to 6.0.20 (exclusive). This makes it possible for unauthenticated attackers to dismiss admin notices.
- Affected:
- up to 6.0.20
- Fixed in:
- 6.0.20
- Disclosed:
- Dec 8, 2023
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.14
unknown
[en] The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admi...
- Affected:
- up to 6.0.14
- Fixed in:
- 6.0.14
- Disclosed:
- Mar 28, 2022
CVE-2022-0770 on NVD →
Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 - Missing Authorization to Sensitive Information Disclosure
high
The Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 WordPress plugins do not have proper capabilities checks in the /wp-content/plugins/gtranslate/url_addon/gtranslate.php file which writes debug data such as user's cookies in a publicly accessible file when t...
- CVSS:
- 8.8
- Affected:
- up to 6.0.13
- Fixed in:
- 6.0.14
- Disclosed:
- Mar 7, 2022
CVE-2022-0770 on NVD →
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.12
unknown
[en] The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 6.0.12
- Fixed in:
- 6.0.12
- Disclosed:
- Nov 8, 2021
CVE-2021-24594 on NVD →
Translate WordPress - Google Language Translator <= 6.0.11 - Admin+ Stored Cross-Site Scripting
medium
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 4.8
- Affected:
- up to 6.0.12
- Fixed in:
- 6.0.12
- Disclosed:
- Oct 5, 2021
CVE-2021-24594 on NVD →
Translate WordPress - Google Language Translator < 6.0.12 - Admin+ Stored Cross-Site Scripting
medium
- Affected:
- up to 6.0.12
- Fixed in:
- 6.0.12
- Disclosed:
- Oct 5, 2021
CVE-2021-24594 on NVD →
Google Language Translator <= 6.0.9 - Reflected Cross-Site Scripting
high
The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 7.1
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Jul 21, 2021
CVE-2021-4452 on NVD →
Google Language Translator < 6.0.10 - Authenticated (author+) Cross-Site Scripting (XSS)
medium
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Jul 21, 2021
Google Language Translator < 6.0.10 - Authenticated Cross-Site Scripting (XSS)
medium
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Jul 21, 2021
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.10
unknown
The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Jul 21, 2021
Google Language Translator <= 6.0.9 - Authenticated Cross-Site Scripting
medium
The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Scripting via the glt shortcode in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers at the Author level to inject arbitrary web scripts in pa...
- CVSS:
- 6.4
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Jul 20, 2021
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.10
unknown
The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Scripting via the glt shortcode in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers at the Author level to inject arbitrary web scripts in pa...
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Jul 20, 2021
Translate WordPress – Google Language Translator [google-language-translator] < 5.0.06
unknown
[en] The google-language-translator plugin before 5.0.06 for WordPress has XSS.
- Affected:
- up to 5.0.06
- Fixed in:
- 5.0.06
- Disclosed:
- Aug 13, 2019
CVE-2016-10870 on NVD →
Google Language Translator <= 5.0.05 - XSS
medium
- Affected:
- up to 5.0.06
- Fixed in:
- 5.0.06
- Disclosed:
- Apr 19, 2016
CVE-2016-10870 on NVD →
Google Language Translator <= 5.0.05 - Cross-Site Scripting
medium
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 5.0.06
- Fixed in:
- 5.0.06
- Disclosed:
- Apr 18, 2016
CVE-2016-10870 on NVD →
Google Language Translator <= 4.0.9 - Authenticated Stored Cross-Site Scripting
medium
The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.9 via 'the googlelanguagetranslator_flags_order' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
- Disclosed:
- Aug 13, 2015
Translate WordPress – Google Language Translator [google-language-translator] < 5.0.0
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Vulnerable parameter is "googlelanguagetranslator_flags_order".
Upgrade this plugin.
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
- Disclosed:
- Aug 13, 2015
Translate WordPress – Google Language Translator [google-language-translator] < 5.0.0
unknown
The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.9 via 'the googlelanguagetranslator_flags_order' parameter due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web script...
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
- Disclosed:
- Aug 13, 2015
Google Language Translator < 5.0.0 - Authenticated Cross-Site Scripting (XSS)
medium
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
- Disclosed:
- Aug 13, 2015
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.10
unknown
The plugin was vulnerable to Authenticated Cross-Site Scripting (XSS) allowing a user with Author role to execute malicious JavaScript via the glt shortcode.
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
Translate WordPress – Google Language Translator [google-language-translator] < 6.0.10
unknown
The plugin was vulnerable to Authenticated Cross-Site Scripting (XSS) only affecting older web browsers such as Internet Explorer <= 9.
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
Translate WordPress – Google Language Translator [google-language-translator] < 5.0.0
unknown
The Translate WordPress – Google Language Translator WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database