XSS Vulnerability in qTranslate Plugin for WordPress
CVE-2015-5535
Currently unrated
Summary
The qTranslate plugin for WordPress suffers from a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML into the application. This exploitation occurs through the 'edit' parameter in the qtranslate page located at wp-admin/options-general.php. Attackers can leverage this flaw to execute malicious scripts in the context of unsuspecting users' browsers, potentially leading to unauthorized actions and compromise of sensitive data.
References
Timeline
Vulnerability published
Vulnerability Reserved