Web / CMS
Cross-Site Scripting (XSS)
Reflected XSS in GTranslate wordpress plugin
Reflected XSS in GTranslate plugin of wordpress The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link.
6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS30
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-11930
VENDORS
GTranslate
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
GTranslate (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
.png)
Summary
Overview
Reflected XSS in GTranslate plugin of wordpress
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
Vulnerability details
Vulnerability details
CVE-2020-11930
CWE-79
Medium | 6.1
Reflected XSS in GTranslate plugin of wordpress The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE
Disclosure timeline
2020-02-10 reported to the vendor
2020-02-18 Fixed by vendor
2020-04-20 CVE assigned
References
Credits
Gaurav Nayak.
















