In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2021-07-30T20:45:07.508762Z
Updated: 2024-09-17T01:15:37.501Z
Reserved: 2021-06-10T00:00:00
Link: CVE-2021-34630
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-07-30T21:15:08.910
Modified: 2024-11-21T06:10:50.953
Link: CVE-2021-34630
Redhat
No data.