Description
WordPress Plugin qTranslate is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin qTranslate version 2.5.34 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.35 or latest
References
Related Vulnerabilities
Jenkins Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1999044)
WordPress Plugin Comment Extra Fields Multiple Cross-Site Scripting Vulnerabilities (1.7)
PHP Other Vulnerability (CVE-2014-4670)
WordPress Plugin Plainview Activity Monitor Remote Command Execution (20161228)