plugin

My Wp Translate Vulnerabilities

8 known security issues reported for the My Wp Translate WordPress plugin. Most recent disclosed Sep 10, 2025.

2 high 2 medium

Running My Wp Translate on your site? Check whether your installed version is affected.

Scan your site free

My WP Translate <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

high

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_import_strings() function in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level a...

CVSS:
8.8
Affected:
up to 1.1
Fix:
No patched version reported
Disclosed:
Sep 10, 2025

CVE-2025-8425 on NVD →

My WP Translate <= 1.1 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Option Read and Deletion

medium

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_code() functions in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
5.4
Affected:
up to 1.1
Fix:
No patched version reported
Disclosed:
Sep 10, 2025

CVE-2025-8423 on NVD →

My WP Translate [my-wp-translate] < 1.0.4 (closed)

unknown

[en] The my-wp-translate plugin before 1.0.4 for WordPress has XSS.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Aug 20, 2019

CVE-2017-18568 on NVD →

My WP Translate [my-wp-translate] < 1.0.4 (closed)

unknown

[en] The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Aug 20, 2019

CVE-2017-18569 on NVD →

My WP Translate [my-wp-translate] < 1.0.4 (closed)

unknown

WordPress My WP Translate plugin Authenticated Option Deletion Vulnerability was found in 1.0.3 version and exists in the function ajax_mtswpt_remove_plugin() accessible through WordPress AJAX functionality to users who are logged in.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Oct 11, 2017

My WP Translate <= 1.0.3 - Reflected Cross-Site Scripting

medium

The My WP Translate plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on the 'tab' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browse...

CVSS:
6.1
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Oct 10, 2017

CVE-2017-18568 on NVD →

My WP Translate <= 1.0.3 - Unprotected AJAX Actions

high

The My WP Translate plugin for WordPress is vulnerable to an authorization bypass weakness in versions up to, and including, 1.0.3. This is due to missing capability checks and nonce validation on the following functions: ajax_translation_panel(), ajax_save_translation(), ajax_add_plugin(), ajax_remove_plugin(), ajax_s...

CVSS:
8
Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Oct 9, 2017

CVE-2017-18569 on NVD →

My WP Translate [my-wp-translate] <= 1.1 (unfixed)

unknown
Affected:
up to 1.1
Fix:
No patched version reported

CVE-2025-8425 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database