Vulnerability Description
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Transposh | Transposh Wordpress Translation | < 1.0.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/b5cbebf4-5749-41a0-8be3-3333853fca17ExploitThird Party Advisory
- https://wpscan.com/vulnerability/b5cbebf4-5749-41a0-8be3-3333853fca17ExploitThird Party Advisory
FAQ
What is CVE-2021-24910?
CVE-2021-24910 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the cu...
How severe is CVE-2021-24910?
CVE-2021-24910 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24910?
Check the references section above for vendor advisories and patch information. Affected products include: Transposh Transposh Wordpress Translation.