CVE-2021-24610
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.
El plugin TranslatePress de WordPress versiones anteriores a 2.0.9, no implementa una sanitización apropiada en las cadenas traducidas. La función "trp_sanitize_string" sólo elimina la etiqueta script con una regex, permitiendo todavía que otras etiquetas y atributos HTML ejecuten javascript, que podría conllevar a problemas de tipo Cross-Site Scripting Almacenado autenticado
WordPress TranslatePress plugin version 2.0.8 suffers from a persistent cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-08-30 CVE Published
- 2021-09-28 First Exploit
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cozmoslabs Search vendor "Cozmoslabs" | Translatepress Search vendor "Cozmoslabs" for product "Translatepress" | < 2.0.9 Search vendor "Cozmoslabs" for product "Translatepress" and version " < 2.0.9" | wordpress |
Affected
|