> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> WordPress Transposh: Exploiting a Blind SQL Injection via XSS

[SOURCE] RCE Security [AUTHOR: Julien Ahrens] [DATE: 22/07/2022 14:40] [LANGUAGE: EN]
Introduction You probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which resulted in more than $30,000 in bounties: [CVE-2021-24910] Transposh <= 1.0.7 “tp_tp” Unauthenticated Reflected Cross-Site Scripting [CVE-2021-24911] Transposh <= 1.0.7 “tp_translation” Unauthenticated Stored Cross-Site Scripting [CVE-2021-24912] Transposh <= 1.0.8.1 Multiple Cross-Site Request Forgeries [CVE-2022-2461] Transposh […]
[messages.read_original_source] →