Security Advisory

CVE-2021-25103

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-02-07 15:47:21
Last updated 2024-08-03 19:56:10
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY