CVE-2020-11930: XSS
Published Apr 20, 2020
·Updated
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
Affected Software
1 affected component
GTranslate Translate WordPress with GTranslate WordPress<2.8.52
Remediation
Event History
Apr 20, 2020
CVE Published
via MITRE·12:07 AM
Data Sourced
via MITRE·12:07 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11930?
CVE-2020-11930 is classified as a moderate severity vulnerability due to its potential for reflected cross-site scripting (XSS).
2
How do I fix CVE-2020-11930?
To fix CVE-2020-11930, you should update the GTranslate plugin to version 2.8.52 or later.
3
What type of vulnerability is CVE-2020-11930?
CVE-2020-11930 is a reflected cross-site scripting (XSS) vulnerability that can be exploited through crafted links.
4
What software is affected by CVE-2020-11930?
CVE-2020-11930 affects versions of the GTranslate plugin for WordPress prior to 2.8.52.
5
Is user action required to exploit CVE-2020-11930?
Yes, exploiting CVE-2020-11930 requires a user to click on a specially crafted link.