GTranslate <= 3.0.3 - Authenticated (Administrator+) Cross-Site Scripting via Multiple Parameters
medium
The GTranslate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fincl_langs', 'incl_langs' and 'alt_flags' parameters in versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...
- CVSS:
- 4.4
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.4
- Disclosed:
- Aug 25, 2023
CVE-2023-4502 on NVD →
Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 - Missing Authorization to Sensitive Information Disclosure
high
The Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 WordPress plugins do not have proper capabilities checks in the /wp-content/plugins/gtranslate/url_addon/gtranslate.php file which writes debug data such as user's cookies in a publicly accessible file when t...
- CVSS:
- 8.8
- Affected:
- up to 2.9.9
- Fixed in:
- 2.9.9
- Disclosed:
- Mar 7, 2022
CVE-2022-0770 on NVD →
Translate WordPress with GTranslate <= 2.9.6 - Reflected Cross-Site Scripting
medium
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT...
- CVSS:
- 4.7
- Affected:
- up to 2.9.7
- Fixed in:
- 2.9.7
- Disclosed:
- Jan 10, 2022
CVE-2021-25103 on NVD →
GTranslate Pro and GTranslate Enterprise <= 2.8.64 - Reflected Cross-Site Scripting
medium
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected X...
- CVSS:
- 5.8
- Affected:
- up to 2.8.65
- Fixed in:
- 2.8.65
- Disclosed:
- Jul 23, 2021
CVE-2021-34630 on NVD →
GTranslate <= 2.8.51 - Reflected Cross Site Scripting
medium
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
- CVSS:
- 6.1
- Affected:
- up to 2.8.51
- Fixed in:
- 2.8.52
- Disclosed:
- Apr 20, 2020
CVE-2020-11930 on NVD →
Translate WordPress with GTranslate <= 2.8.10 - Open Redirect
medium
The Google Translate Plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.8.10. This is due to the application failing to properly verify user-supplied input from the `gurl` parameter. This makes it possible for unauthenticated attackers to exploit this issue and redirect users to arb...
- CVSS:
- 6.1
- Affected:
- up to 2.8.11
- Fixed in:
- 2.8.11
- Disclosed:
- Feb 3, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database