CVE-2023-1119: Srbtranslatin Project Srbtranslatin
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.
Affected products
- Srbtranslatin Project Srbtranslatin: before 2.4 (fixed in 2.4)
- Updraftplus Wp-Optimize: before 3.2.13 (fixed in 3.2.13)
Published 2023-07-10. Last modified 2026-06-17.