cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forconveythis-translate conveythis-translate

Direction: descending
Dec 11, 2025

Language Translate Widget for WordPress – ConveyThis # CVE-2025-62152

CVE, Research URL

CVE-2025-62152

Date
Dec 09, 2025
Research Description
Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 268.10.
Affected versions
max 268.10.
Status
vulnerable
Oct 11, 2025

Language Translate Widget for WordPress &#8211; ConveyThis # CVE-2025-57919

CVE, Research URL

CVE-2025-57919

Date
Sep 23, 2025
Research Description
Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for WordPress – ConveyThis allows Object Injection. This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 264.
Affected versions
max 266.
Status
vulnerable
Jul 26, 2024

Language Translate Widget for WordPress &#8211; ConveyThis # CVE-2024-38792

CVE, Research URL

CVE-2024-38792

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in ConveyThis Translate Team Language Translate Widget for WordPress – ConveyThis allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 234.
Affected versions
max 235.
Status
vulnerable
Jun 07, 2024

Language Translate Widget for WordPress &#8211; ConveyThis # CVE-2023-6811

CVE, Research URL

CVE-2023-6811

Date
Apr 11, 2024
Research Description
The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 224.
Status
vulnerable