WordPress Transposh Translation plugin before 1.0.8 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response.
View the template here CVE-2021-24910.yaml
References:
https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-24910.txt