Input validation vulnerability in Prisna GWT – Google Website Translator 1.4.13

The Prisna GWT plugin used for translating websites on WordPress is at risk for a type of hacker attack called Stored Cross-Site Scripting. This is because the plugin does not properly clean up the input and output of its admin settings, leaving it open to malicious code being inserted into pages. Attackers with administrator access can exploit this vulnerability to inject their own code into pages, which will then run whenever a user visits that page. This only affects websites with multiple installations and those that have disabled a security feature called unfiltered_html.

Detected in:

Prisna GWT – Google Website Translator fixed vulnerable versions: >= * <= 1.4.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.