Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High1
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-05-02

CVE-2023-4502 - Translate Wordpress With Gtranslate Plugin

The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters.

PLUGIN Translate Wordpress With Gtranslate

CVE-2023-4502

MEDIUM CVSS 4.8 2023-09-25
Threat Entry Updated 2024-11-21

CVE-2022-0770 - Translate Wordpress With Gtranslate Plugin

The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page

PLUGIN Translate Wordpress With Gtranslate

CVE-2022-0770

HIGH CVSS 8.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-25103 - Translate Wordpress With Gtranslate Plugin

The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY

PLUGIN Translate Wordpress With Gtranslate

CVE-2021-25103

MEDIUM CVSS 4.7 2022-02-07
Scroll to top