CVE Database
/

CVE-2021-25103

Back to search

CVE-2021-25103

Published: Feb 7, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY

VendorProductVersions

Unknown

Translate WordPress with GTranslate

affected
2.9.7 - < 2.9.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now