CVE-2021-24594
EUVD-2021-1150608.11.2021, 18:15
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gtranslate | google_language_translator | 𝑥 < 6.0.12 |
𝑥
= Vulnerable software versions