Impact
Improper neutralization of input during web page generation allows a stored cross‑site scripting flaw in the Translate This gTranslate Shortcode plugin. An attacker can craft and store malicious script payloads that will execute in the browsers of users viewing affected pages. The CVSS score of 6.5 indicates a moderate risk of exploitation.
Affected Systems
The vulnerability affects the Translate This gTranslate Shortcode WordPress plugin supplied by reubenthiessen, for all releases up to and including version 1.0. Sites running these versions should review their plugin versions as the issue has not been resolved in the available release.
Risk and Exploitability
The EPSS score of less than 1% indicates low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The stored XSS flaw can allow an attacker to inject and store malicious scripts that will run in visitors’ browsers when they view affected content. While the CVSS score of 6.5 reflects a moderate severity, the impact is confined to the browsers of site visitors and depends on the attacker’s ability to inject the payload.
OpenCVE Enrichment
EUVD