.. / CVE-2021-24910

Exploit for WordPress Transposh Translation <1.0.8 - Cross-Site Scripting (CVE-2021-24910)

Description:

WordPress Transposh Translation plugin before 1.0.8 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response.

Nuclei Template

View the template here CVE-2021-24910.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24910.yaml
Copy

References:

https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-24910.txt
https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-24910
https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/
https://wpscan.com/vulnerability/b5cbebf4-5749-41a0-8be3-3333853fca17