Eklenti güvenlik geçmişi
GPTranslate güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI eklentisi için 4 açık kaydı bulunuyor; en yenisi 8 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 4 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 2.34.14.
- Toplam kayıt
- 4
- Kritik veya yüksek
- 3
- Oturumsuz istismar
- 4
- Son kayıt
- 8 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.34.14 öncesi · Oturum açmadan istismar edilebilir
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
Türkçe kayıt ve ne yapmalıhassas bilgi ifşası
Etkilenen sürümler: 2.34.6 ve öncesi · Oturum açmadan istismar edilebilir
The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission.
SQL enjeksiyonu
Etkilenen sürümler: 2.32.6 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.31 ve öncesi · Oturum açmadan istismar edilebilir
The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all versions up to, and including, 2.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The deterministically derived API key (sha256 of the site URL) is printed in the HTML source of every page via the JavaScript variable gptApiKey, meaning any unauthenticated visitor can retrieve the key and submit malicious translation payloads to the /wp-json/gptranslate/v1/request endpoint without any additional precondition.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.