Impact
The GTranslate WordPress plugin versions prior to 5.0.1 fails to strip shortcodes from the body of outgoing emails before the translation expansion occurs. This oversight allows an unauthenticated user to register and inject arbitrary shortcode tags, which are then executed on the server side. The execution of these shortcodes can lead to the manipulation of email content, potential code execution, or other unintended behavior, compromising the integrity and confidentiality of the site. The CVSS score of 4.8 indicates moderate overall severity for this flaw.
Affected Systems
WordPress sites that have the GTranslate plugin installed in a pre‑5.0.1 version are vulnerable. The plugin’s vendor is listed as GTranslate, and any installation that has not been upgraded to 5.0.1 or later is at risk.
Risk and Exploitability
The vulnerability has a moderate CVSS score and no EPSS score is currently available, indicating that the likelihood of exploitation has not been quantified. The flaw is not listed in the CISA KEV catalog. The likely attack path requires an unauthenticated user to trigger the email translation feature on a site that hosts custom or arbitrary shortcodes. By supplying a crafted shortcode payload, the attacker can force the plugin to expand and execute it server side, producing the impact described. Moderately high risk remains for sites with active email translation and numerous shortcodes.
OpenCVE Enrichment