XSS Vulnerability in qTranslate Plugin for WordPress
CVE-2015-5535

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
13 August 2015

Summary

The qTranslate plugin for WordPress suffers from a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML into the application. This exploitation occurs through the 'edit' parameter in the qtranslate page located at wp-admin/options-general.php. Attackers can leverage this flaw to execute malicious scripts in the context of unsuspecting users' browsers, potentially leading to unauthorized actions and compromise of sensitive data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.