VYPR

Weglot

by WordPress

Source repositories

CVEs (2)

  • CVE-2024-2124MedMar 20, 2024
    risk 0.42cvss 6.4epss 0.01

    The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 4.2.5 due to insufficient input sanitization and output escaping on user supplied…

  • CVE-2025-10008MedOct 30, 2025
    risk 0.27cvss 5.3epss 0.00

    The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clean_options' function in all versions up to, and including, 5.1. This makes it possible for unauthenticated…