CVE · Medium

CVE-2021-24594 — Translate WordPress – Google Language Translator [google-language-translator] < 6.0.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24594 Translate WordPress – Google Language Translator [google-language-translator] < 6.0.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 6.0.12 6.0.12 2021-10-05

CVE-2021-24594

The Translate WordPress – Google Language Translator plugin prior to version 6.0.12 failed to properly sanitize and escape certain configuration options before displaying them on multiple pages within WordPress. This weakness allowed administrators and other high-privilege users to inject malicious scripts through the plugin settings, bypassing protections that normally prevent unfiltered HTML input. The vulnerability enabled stored cross-site scripting attacks that could affect any user who viewed the affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.