{"api_version":"1","generated_at":"2026-06-04T09:39:54+00:00","cve":"CVE-2023-4502","urls":{"html":"https://cve.report/CVE-2023-4502","api":"https://cve.report/api/cve/CVE-2023-4502.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-4502","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-4502"},"summary":{"title":"CVE-2023-4502","description":"The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters.","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2023-09-25 16:15:00","updated_at":"2023-11-07 04:22:00"},"problem_types":[],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/e4804850-2ac2-4cec-bc27-07ed191d96da","name":"https://wpscan.com/vulnerability/e4804850-2ac2-4cec-bc27-07ed191d96da","refsource":"MISC","tags":[],"title":"Translate WordPress with GTranslate < 3.0.4 - Admin+ Stored XSS WordPress Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-4502","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4502","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"4502","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gtranslate","cpe5":"translate_wordpress_with_gtranslate","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-4502","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross-Site Scripting (XSS)"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Translate WordPress with GTranslate","version":{"version_data":[{"version_affected":"<","version_name":"0","version_value":"3.0.4"}]}}]}}]}},"references":{"reference_data":[{"url":"https://wpscan.com/vulnerability/e4804850-2ac2-4cec-bc27-07ed191d96da","refsource":"MISC","name":"https://wpscan.com/vulnerability/e4804850-2ac2-4cec-bc27-07ed191d96da"}]},"generator":{"engine":"WPScan CVE Generator"},"source":{"discovery":"EXTERNAL"},"credits":[{"lang":"en","value":"Pablo Sanchez"},{"lang":"en","value":"WPScan"}]},"nvd":{"publishedDate":"2023-09-25 16:15:00","lastModifiedDate":"2023-11-07 04:22:00","problem_types":[],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.7,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gtranslate:translate_wordpress_with_gtranslate:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"3.0.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}