WordPress Transposh Translation plugin before 1.0.8 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response.
id: CVE-2021-24910
info:
name: WordPress Transposh Translation <1.0.8 - Cross-Site Scripting
au
...