CVE · Medium

CVE-2020-11930 — Translate WordPress with GTranslate [gtranslate] < 2.8.52

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-11930 Translate WordPress with GTranslate [gtranslate] < 2.8.52 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.8.52 2.8.52 2020-04-20

CVE-2020-11930

The GTranslate plugin for WordPress versions before 2.8.52 contained an unauthenticated reflected cross-site scripting flaw that could be exploited through a malicious link, specifically when the hreflang tags feature was enabled with paid sub-domain or sub-directory options. The issue stemmed from the plugin's failure to properly escape the WordPress add_query_arg function before outputting its results to the page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.