cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forgtranslate gtranslate

Direction: ascending
Jun 07, 2024

Translate WordPress with GTranslate # CVE-2021-34630

CVE, Research URL

CVE-2021-34630

Date
Jul 31, 2021
Research Description
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.
Affected versions
max 2.8.65.
Status
vulnerable

Translate WordPress with GTranslate # CVE-2021-25103

CVE, Research URL

CVE-2021-25103

Date
Feb 07, 2022
Research Description
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY
Affected versions
max 2.9.7.
Status
vulnerable

Translate WordPress with GTranslate # CVE-2020-11930

CVE, Research URL

CVE-2020-11930

Date
Apr 20, 2020
Research Description
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
Affected versions
max 2.8.52.
Status
vulnerable

Translate WordPress with GTranslate # CVE-2022-0770

CVE, Research URL

CVE-2022-0770

Date
Mar 28, 2022
Research Description
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page
Affected versions
max 2.9.9.
Status
vulnerable

Translate WordPress with GTranslate # CVE-2023-4502

CVE, Research URL

CVE-2023-4502

Date
Sep 25, 2023
Research Description
The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters.
Affected versions
max 3.0.4.
Status
vulnerable
Feb 04, 2026

Translate WordPress with GTranslate # PSC-2026-64605

PSC, Research URL

PSC-2026-64605

Date
Feb 04, 2026
Research Description
Translate WordPress with GTranslate (v3.0.9) is a multilingual WordPress solution that uses Google Translate automatic translation to make a site available in 103 languages, dramatically expanding reach to more than 99% of internet users. Since GTranslate has been providing website translation services since 2008, the plugin is built around a mature translation platform and a cloud-based approach that aims to keep the WordPress site fast—translations are delivered without heavy on-site processing. In paid editions, GTranslate adds full multilingual SEO capabilities (subdomains/subdirectories, indexable translations, translated metadata, hreflang, and more), helping websites grow international traffic and sales. Because translation plugins operate on nearly every frontend pageview, output user-visible content dynamically, and may modify SEO metadata and URL structures, security must be treated as a primary requirement. That’s why it’s important that GTranslate v3.0.9 has passed CleanTalk Plugin Security Certification (PSC-2026-64605), confirming the plugin was reviewed and validated against critical vulnerability classes and secure-coding expectations.
Affected versions
Min 3.1.2, max 3.1.2.
Status
SAFE & CERTIFIED
Jun 16, 2026

Translate WordPress with GTranslate # ddc3b0e982fb05d69c6d7a92d4d96a75b2c57846

Date
Aug 01, 2014
Research Description
Translate WordPress with GTranslate [gtranslate] < 1.0.13 WordPress GTranslate Plugin <= 1.0.12 - Cross Site Request Forgery This plugin is prone to a cross site request forgery vulnerability. Update the plugin.
Affected versions
max 1.0.13.
Status
vulnerable

Translate WordPress with GTranslate # d4da110e-4351-49b8-b7a1-8be24895d2fa

Date
-
Research Description
Translate WordPress with GTranslate [gtranslate] < 2.8.11 GTranslate &lt; 2.8.11 - Unauthenticated Open Redirect The Translate WordPress with GTranslate WordPress plugin was affected by an Unauthenticated Open Redirect security vulnerability.
Affected versions
max 2.8.11.
Status
vulnerable

Translate WordPress with GTranslate # 531e4f0bd44fc7742e764c6c8b32d6bb844afcc2

Date
Feb 03, 2017
Research Description
Translate WordPress with GTranslate [gtranslate] < 2.8.11 Translate WordPress with GTranslate <= 2.8.10 - Open Redirect The Google Translate Plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.8.10. This is due to the application failing to properly verify user-supplied input from the `gurl` parameter. This makes it possible for unauthenticated attackers to exploit this issue and redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible.
Affected versions
max 2.8.11.
Status
vulnerable

Translate WordPress with GTranslate # f34d0907-5c13-4e9e-a1e1-547a578c91d1

Date
-
Research Description
Translate WordPress with GTranslate [gtranslate] < 1.0.13 GTranslate 1.0.12 - gtranslate.php Widget Code Editing CSRF The Translate WordPress with GTranslate WordPress plugin was affected by a gtranslate.php Widget Code Editing CSRF security vulnerability.
Affected versions
max 1.0.13.
Status
vulnerable

Translate WordPress with GTranslate # bc6b192e408cdd968a35e53a6eaf2e2ee6fd242e

Date
Aug 25, 2023
Research Description
Translate WordPress with GTranslate [gtranslate] < 3.0.4 GTranslate <= 3.0.3 - Authenticated (Administrator+) Cross-Site Scripting via Multiple Parameters The GTranslate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fincl_langs', 'incl_langs' and 'alt_flags' parameters in versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 3.0.4.
Status
vulnerable

Translate WordPress with GTranslate # d78881590e4a94515b519383745e5cc4d843ab15

Date
Sep 01, 2023
Research Description
Translate WordPress with GTranslate [gtranslate] < 3.0.4 WordPress GTranslate Plugin < 3.0.4 is vulnerable to Cross Site Scripting (XSS) No patched version available. Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress GTranslate Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has not been known to be fixed yet.
Affected versions
max 3.0.4.
Status
vulnerable
Sep 13, 2026

Translate WordPress with GTranslate # CVE-2025-15695

CVE, Research URL

CVE-2025-15695

Date
Sep 11, 2026
Research Description
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.
Affected versions
max 3.0.10.
Status
vulnerable