PT-2022-9505 · WordPress · Transposh Wordpress Translation Plugin

Julien Ahrens

·

Published

2022-07-28

·

Updated

2022-08-25

·

CVE-2021-24911

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Transposh WordPress Translation plugin versions prior to 1.0.8
Description The issue is related to Stored Cross-Site Scripting. It occurs because the tk0 parameter from the tp translation AJAX action is not properly sanitized and escaped. This leads to the execution of malicious scripts in the admin dashboard of the plugin. The minimum role required to perform such an attack depends on the plugin's "Who can translate?" setting.
Recommendations For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the tp translation AJAX action or disabling the tk0 parameter until a patch is applied. Additionally, review and adjust the "Who can translate?" setting to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-24911

Affected Products

Transposh Wordpress Translation Plugin