Impact
XSS flaw in the Transliterator plugin allows unauthenticated users to inject scripts into comment content using the predictable {rstr_keep} placeholder. The plugin does not properly sanitize these tokens and relies on WordPress’ permissive kses filter, letting tags such as <a> and <code> survive. As a result, malicious scripts persist in the database and execute whenever a user views the page, enabling arbitrary JavaScript execution, cookie theft, and potential remote code execution via the user’s browser.
Affected Systems
All versions of the Transliterator – Multilingual and Multi‑script Text Conversion plugin for WordPress up to and including 2.5.8 are affected. The vendor is ivijanstefan.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, but no EPSS score is published, and it is not listed in CISA’s KEV catalog. The flaw can be exploited by any user who can post a comment on a WordPress site running a vulnerable plugin version; the attack vector is entirely web‑based and does not require authentication. Once injected, the malicious payload runs in the context of any visitor to the affected page, giving attackers the ability to deface content, steal session cookies, or perform further attacks on the victim’s browser.
OpenCVE Enrichment