qTranslate <= 2.5.39 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the qTranslate plugin 2.5.39 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the edit parameter in the qtranslate page to wp-admin/options-general.php.
- CVSS:
- 6.1
- Affected:
- up to 2.5.39
- Fix:
- No patched version reported
- Disclosed:
- Jul 29, 2015
CVE-2015-5535 on NVD →
qTranslate <= 2.5.39 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
- CVSS:
- 8.8
- Affected:
- up to 2.5.39
- Fix:
- No patched version reported
- Disclosed:
- Jun 23, 2013
CVE-2013-3251 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database