Vulnerability Description
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gtranslate | Translate Wordpress With Gtranslate | < 2.9.7 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/90067336-c039-4cbe-aa9f-5eab5d1e1c3dExploitThird Party Advisory
- https://wpscan.com/vulnerability/90067336-c039-4cbe-aa9f-5eab5d1e1c3dExploitThird Party Advisory
FAQ
What is CVE-2021-25103?
CVE-2021-25103 is a vulnerability with a CVSS score of 4.7 (MEDIUM). The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, ...
How severe is CVE-2021-25103?
CVE-2021-25103 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25103?
Check the references section above for vendor advisories and patch information. Affected products include: Gtranslate Translate Wordpress With Gtranslate.