SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34630

Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the…

MEDIUM 6.1EPSS 1.57%

Does this matter?

Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.

Description

In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.57% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-116, CWE-79
Affected
gtranslate/gtranslate
Source
security@wordfence.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.