CVE-2020-11930: Gtranslate Translate WordPress With Gtranslate

Medium severity, CVSS 6.1. EPSS: 4.5% chance of exploitation in the next 30 days.

The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

Affected products

  • Gtranslate Translate WordPress With Gtranslate: before 2.8.52 (fixed in 2.8.52)

Published 2020-04-20. Last modified 2026-06-17.