Wpglobus is a WordPress translation and localization plugin that sits within the content-management ecosystem, where its vulnerabilities center on a narrow product line. Its disclosures are characterized by web-application input-handling weaknesses, principally cross-site scripting and cross-site request forgery, which reflect the plugin's role in content processing and user interaction within WordPress environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpglobus over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5361HIGH The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php. | Jan 12, 2018 | 8.8 | 26 | NO | NO |
CVE-2023-25711MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGlobus WPGlobus Translate Options plugin <= 2.1.0 versions. | Apr 7, 2023 | 6.1 | 20 | NO | NO |
CVE-2018-5366MEDIUM The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php. | Jan 12, 2018 | 4.8 | 17 | NO | NO |
CVE-2018-5364MEDIUM The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php. | Jan 12, 2018 | 4.8 | 17 | NO | NO |
CVE-2018-5363MEDIUM The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-adm | Jan 12, 2018 | 4.8 | 17 | NO | NO |
CVE-2018-5362MEDIUM The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php. | Jan 12, 2018 | 4.8 | 17 | NO | NO |
CVE-2018-5367MEDIUM The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php. | Jan 12, 2018 | 4.8 | 16 | NO | NO |
CVE-2018-5365MEDIUM The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php. | Jan 12, 2018 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpglobus.
Media articles that mention a CVE ID that affects a product developed by Wpglobus — matched by CVE ID, not by vendor name.