5.4

CVE-2022-0765

Exploit

Loco Translate < 2.6.1 - Authenticated Stored Cross-Site Scripting

Loco Translate <= 2.6.0 - Authenticated Stored Cross-Site Scripting

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.
Mögliche Gegenmaßnahme
Loco Translate: Update to version 2.6.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Loco Translate ProjectLoco Translate SwPlatformwordpress Version < 2.6.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Loco Translate
Version [*, 2.6.1)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.01% 0.892
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/58838f51-323d-41e0-8c85-8e113dc2c587
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/4d3b1a76-febc-4037-b31e-5987f8a23e92
Third Party Advisory