SrbTransLatin – Serbian Latinisation [srbtranslatin] <= 3.2.0 (unfixed)
unknown
[en] Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Oblak Studio Srbtranslatin allows Retrieve Embedded Sensitive Data.This issue affects Srbtranslatin: from n/a through 3.2.0.
- Affected:
- up to 3.2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-31421 on NVD →
Srbtranslatin <= 3.2.0 - Unauthenticated Sensitive Information Exposure
medium
The SrbTransLatin – Serbian Latinisation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31421 on NVD →
WP-Optimize <= 3.2.12 & SrbTransLatin <= 2.4 - Stored/Reflected Cross-Site Scripting via Third Party Library
medium
The WP-Optimize plugin and SrbTransLatin plugin for WordPress are vulnerable to Cross-Site Scripting via the 's' parameter in WP-Optimize in versions up to 3.2.12 and via post content in SrbTransLatin in versions up to, and including, 2.4 due to a third party library that strips some escaping. This makes it possible fo...
- CVSS:
- 6.1
- Affected:
- up to 2.4
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 4, 2023
CVE-2023-1119 on NVD →
SrbTransLatin – Serbian Latinisation [srbtranslatin] < 1.47
unknown
[en] The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.
- Affected:
- up to 1.47
- Fixed in:
- 1.47
- Disclosed:
- Jan 12, 2018
CVE-2018-5368 on NVD →
SrbTransLatin – Serbian Latinisation [srbtranslatin] < 1.4.7
unknown
[en] The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php with a lang_identificator parameter.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Jan 12, 2018
CVE-2018-5369 on NVD →
SrbTransLatin – Serbian Latinisation [srbtranslatin] < 1.4.7
unknown
Stored Cross-site scripting (XSS) and Cross-site request forgery (CSRF) vulnerabilities were found in WordPress Srbtranslatin in 1.4.6 version.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Jan 12, 2018
SrbTransLatin <= 1.46 - Cross-Site Request Forgery
high
The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.
- CVSS:
- 8.8
- Affected:
- up to 1.46
- Fixed in:
- 1.47
- Disclosed:
- Jan 11, 2018
CVE-2018-5368 on NVD →
SrbTransLatin – SrbTransLatin <= 1.46 - Cross-Site Scripting
medium
The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php with a lang_identificator parameter.
- CVSS:
- 4.8
- Affected:
- up to 1.46
- Fixed in:
- 1.47
- Disclosed:
- Jan 11, 2018
CVE-2018-5369 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database