CyberRota Analysis
AI-GeneratedThe Translate WordPress with GTranslate plugin prior to version 3.0.10 is vulnerable due to insufficient validation of settings, enabling users with administrator privileges to inject malicious JavaScript that executes in the session of any site visitor. This could lead to session hijacking or other client-side attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.