PT-2026-104510 · WordPress · Transliterator
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Transliterator – Multilingual and Multi-script Text Conversion versions prior to 2.5.9
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) via comment content. This is achieved by using a predictable
{rstr keep} placeholder, enabling the injection of arbitrary web scripts that execute when a user views the affected page. The payload bypasses standard WordPress comment sanitization because the used tags and attributes, such as a[title] and code, are permitted by the core comment kses allow-list, and the plugin's shortcode markers and placeholder tokens are not removed.Recommendations
Update to version 2.5.9 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Transliterator