CVE · Medium

CVE-2024-2124 — Translate WordPress with Weglot – Multilingual AI Translation [weglot] < 4.2.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2124 Translate WordPress with Weglot – Multilingual AI Translation [weglot] < 4.2.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.2.6 4.2.6 2024-03-19

CVE-2024-2124

The Weglot Translate plugin for WordPress contains a cross-site scripting vulnerability in versions before 4.2.6 that could allow an attacker to inject malicious scripts into a website, potentially enabling redirects, advertisements, or other harmful content to execute when visitors access the site. Researcher Ngô Thiên An discovered and reported the flaw. Administrators should upgrade to version 4.2.6 or later to remediate the issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.