CVE-2024-0632 is a Stored Cross-Site Scripting (XSS) vulnerability found in the Automatic Translator with Google Translate WordPress plugin, affecting all versions up to and including 1.5.4. This flaw stems from insufficient input sanitization and output escaping in the custom font setting. It allows authenticated administrators to inject malicious web scripts that execute when a user views an affected page, but only impacts multi-site installations or those with unfiltered_html disabled. The vulnerability has a CVSS score of 4.4 (Medium), indicating a network-based attack with high complexity, requiring high privileges, and resulting in low impact to confidentiality and integrity. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules for Metasploit or Nuclei, or entries in ExploitDB. Community discussion and media coverage are also absent, which is typical for the vast majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Juangirini | Automatic Translator With Google Translate | >= 0, <= 1.5.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.