Description
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY
Published: 2022-02-07
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-12015 The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY
History

No history.

Subscriptions

Gtranslate Translate Wordpress With Gtranslate
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:56:10.614Z

Reserved: 2021-01-14T00:00:00.000Z

Link: CVE-2021-25103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-07T16:15:45.370

Modified: 2024-11-21T05:54:21.437

Link: CVE-2021-25103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses