Medium severity5.4NVD Advisory· Published Aug 22, 2022· Updated Jun 17, 2026
CVE-2021-24911
CVE-2021-24911
Description
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin "Who can translate ?" setting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:transposh:transposh_wordpress_translation:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:transposh:transposh_wordpress_translation:*:*:*:*:*:wordpress:*:*range: <1.0.8
- (no CPE)range: 1.0.8
- Range: <1.0.8
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/bd88be21-0cfc-46bd-b78a-23efc4868a55nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.