CVE-2021-24594: Translate WordPress - Google Language Translator < 6.0.12 - Admin+ Stored Cross-Site Scripting
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Other sources
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24594?
CVE-2021-24594 is classified as a high severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2021-24594?
To mitigate CVE-2021-24594, update the Translate WordPress – Google Language Translator plugin to version 6.0.12 or later.
What types of users are affected by CVE-2021-24594?
CVE-2021-24594 affects high privilege users who can exploit the lack of sanitization and escaping in the plugin's settings.
What kind of attack does CVE-2021-24594 allow?
CVE-2021-24594 allows attackers to perform Cross-Site Scripting (XSS) attacks through the plugin's unsanitized output.
Which versions of the plugin are vulnerable to CVE-2021-24594?
Versions of the Translate WordPress – Google Language Translator plugin prior to 6.0.12 are vulnerable to CVE-2021-24594.