Record summary

CVE-2020-11930 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2020-11930Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 535 B

GitHub

PoC details
GitHubCVE-2020-11930Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 535 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress GTranslate <2.8.52 - Cross-Site ScriptingCVSS 6.1

WordPress GTranslate plugin before 2.8.52 contains an unauthenticated reflected cross-site scripting vulnerability via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

Impact

Attackers can inject malicious JavaScript through a crafted link, potentially stealing user credentials, session tokens, or performing unauthorized actions on behalf of victims when they click the malicious link.

Remediation

Update the WordPress GTranslate plugin to version 2.8.52 or later.

WeaknessesCWE-79
AuthorsdhiyaneshDK
Template tagscve2020cvewordpresswpxsswp-pluginwpscangtranslatevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:gtranslate:translate_wordpress_with_gtranslate:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/gtranslate
FOFA: body=/wp-content/plugins/gtranslate

Source: ProjectDiscovery

References

5