> WordPress Transposh: Exploiting a Blind SQL Injection via XSS
[AUTHOR: Julien Ahrens]
[DATE: 22/07/2022 14:40]
[LANGUAGE: EN]
Introduction You probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which resulted in more than $30,000 in bounties: [CVE-2021-24910] Transposh <= 1.0.7 “tp_tp” Unauthenticated Reflected Cross-Site Scripting [CVE-2021-24911] Transposh <= 1.0.7 “tp_translation” Unauthenticated Stored Cross-Site Scripting [CVE-2021-24912] Transposh <= 1.0.8.1 Multiple Cross-Site Request Forgeries [CVE-2022-2461] Transposh […]