Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical1
High0
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-05-28

CVE-2024-12680 - Google Website Translator Plugin

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Google Website Translator

CVE-2024-12680

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-28

CVE-2024-12679 - Google Website Translator Plugin

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Google Website Translator

CVE-2024-12679

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2024-10-02

CVE-2024-8514 - Google Website Translator Plugin

The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or…

PLUGIN Google Website Translator

CVE-2024-8514

CRITICAL CVSS 9.1 2024-09-25
Scroll to top