Extension WordPress
Vulnérabilités Translate WordPress with GTranslate
Cette page rassemble les failles publiées pour Translate WordPress with GTranslate, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Translate WordPress with GTranslate
6 fiches
GTranslate <= 3.0.3 – Authenticated (Administrator+) Cross-Site Scripting via Multiple Parameters
The GTranslate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fincl_langs', 'incl_langs' and 'alt_flags' parameters in versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 3.0.4)
3.0.4
25/08/2023
Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 – Missing Authorization to Sensitive Information Disclosure
The Translate WordPress with GTranslate
[*, 2.9.9)
2.9.9
07/03/2022
Translate WordPress with GTranslate <= 2.9.6 – Reflected Cross-Site Scripting
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of…
[*, 2.9.7)
2.9.7
10/01/2022
GTranslate Pro and GTranslate Enterprise <= 2.8.64 – Reflected Cross-Site Scripting
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests,…
[*, 2.8.65)
2.8.65
23/07/2021
GTranslate <= 2.8.51 – Reflected Cross Site Scripting
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
*-2.8.51
2.8.52
20/04/2020
Translate WordPress with GTranslate <= 2.8.10 – Open Redirect
The Google Translate Plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.8.10. This is due to the application failing to properly verify user-supplied input from the `gurl` parameter. This makes it possible…
[*, 2.8.11)
2.8.11
03/02/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.