WordPress Transposh 漏洞列表
共找到 4 个与 WordPress Transposh 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2021-24910: WordPress Transposh Translation <1.0.8 - Cross-Site Scripting POC
WordPress Transposh Translation plugin before 1.0.8 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response. -
CVE-2022-2462: WordPress Transposh <=1.0.8.1 - Information Disclosure POC
WordPress Transposh plugin through is susceptible to information disclosure via the AJAX action tp_history, which is intended to return data about who has translated a text given by the token parameter. However, the plugin also returns the user's login name as part of the user_login attribute. If an anonymous user submits the translation, the user's IP address is returned. An attacker can leak the WordPress username of translators and potentially execute other unauthorized operations. -
CVE-2021-24910: WordPress Transposh Translation <1.0.8 - Cross-Site Scripting POC
WordPress Transposh Translation plugin before 1.0.8 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response. -
CVE-2022-2462: WordPress Transposh <=1.0.8.1 - Information Disclosure POC
WordPress Transposh plugin through is susceptible to information disclosure via the AJAX action tp_history, which is intended to return data about who has translated a text given by the token parameter. However, the plugin also returns the user's login name as part of the user_login attribute. If an anonymous user submits the translation, the user's IP address is returned. An attacker can leak the WordPress username of translators and potentially execute other unauthorized operations.