CVE-2020-11930
WordPress GTranslate <2.8.52 - Cross-Site Scripting
Record summary
CVE-2020-11930 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.
Description
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
Exploitation context
Proofs of concept
2Curated repository PoCs
GitHubCVE-2020-11930Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2020-11930Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress GTranslate <2.8.52 - Cross-Site ScriptingCVSS 6.1
WordPress GTranslate plugin before 2.8.52 contains an unauthenticated reflected cross-site scripting vulnerability via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
Impact
Attackers can inject malicious JavaScript through a crafted link, potentially stealing user credentials, session tokens, or performing unauthorized actions on behalf of victims when they click the malicious link.
Remediation
Update the WordPress GTranslate plugin to version 2.8.52 or later.
Source: ProjectDiscovery