CVE-2021-24610

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/09/2021
Last modified:
04/10/2021

Description

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cozmoslabs:translatepress:*:*:*:*:*:wordpress:*:* 2.0.9 (excluding)