Cross-site Scripting Vulnerability in Global Translator Plugin by Pozzad
CVE-2025-30630

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-30630?

The Global Translator plugin developed by Pozzad contains a vulnerability that allows for the improper neutralization of input during web page generation, leading to a Stored Cross-site Scripting (XSS) issue. Attackers could exploit this vulnerability to inject malicious scripts, potentially compromising user data and session integrity. This vulnerability affects versions from n/a through 2.0.2, highlighting the importance of timely updates and security practices for users of the plugin. Ensure your installation is secure and monitor for any signs of compromise.

Affected Version(s)

Global Translator <= 2.0.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.