Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24911
HistoryAug 22, 2022 - 2:56 p.m.

CVE-2021-24911 Transposh WordPress Translation < 1.0.8 - Stored Cross-Site Scripting

2022-08-2214:56:13
CWE-79
WPScan
www.cve.org
3
cve-2021-24911
transposh
wordpress translation
stored cross-site scripting
ajax action tokens
admin dashboard
minimum role

EPSS

0.001

Percentile

24.8%

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin “Who can translate ?” setting.

CNA Affected

[
  {
    "product": "Transposh WordPress Translation",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.0.8",
        "status": "affected",
        "version": "1.0.8",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

24.8%

Related for CVELIST:CVE-2021-24911