Web / CMS

Cross-Site Scripting (XSS)

Reflected XSS in GTranslate wordpress plugin

Reflected XSS in GTranslate plugin of wordpress The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link.

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS30
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-11930
VENDORS
GTranslate
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
GTranslate (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Reflected XSS in GTranslate plugin of wordpress

The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

Vulnerability details

Vulnerability details

CVE-2020-11930
CWE-79
Medium | 6.1

Reflected XSS in GTranslate plugin of wordpress The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2020-02-10 reported to the vendor

2020-02-18 Fixed by vendor

2020-04-20 CVE assigned

Credits

Gaurav Nayak.