.. / CVE-2020-11930

Exploit for WordPress GTranslate <2.8.52 - Cross-Site Scripting (CVE-2020-11930)

Description:

WordPress GTranslate plugin before 2.8.52 contains an unauthenticated reflected cross-site scripting vulnerability via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

Nuclei Template

View the template here CVE-2020-11930.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-11930.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-11930
https://wpscan.com/vulnerability/10181
https://plugins.trac.wordpress.org/changeset/2245591/gtranslate
https://payatu.com/blog/gaurav/analysis-of-cve-2020-11930:-reflected-xss-in-gtranslate-wordpress-module
https://plugins.trac.wordpress.org/changeset/2245581/gtranslate