CVE-2022-2461
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6.
Does this matter?
Lower severity and a low EPSS score (4.79%). Track it; it rarely justifies an emergency change on its own.
Description
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 4.79% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- transposh/transposh wordpress translation
- Source
- security@wordfence.com
References
- https://packetstormsecurity.com/files/167870/wptransposh107-auth.txtExploit, Third Party Advisory, VDB Entry
- https://plugins.trac.wordpress.org/browser/transposh-translation-filter-for-wordpress/trunk/transposh.php?rev=2682425#L1989Patch, Third Party Advisory
- https://www.exploitalert.com/view-details.html?id=38891Exploit, Third Party Advisory
- https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/Exploit, Third Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/223373fc-9d78-47f0-b283-109f8e00b802?source=cveThird Party Advisory
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2461Third Party Advisory
- https://packetstormsecurity.com/files/167870/wptransposh107-auth.txtExploit, Third Party Advisory, VDB Entry
- https://plugins.trac.wordpress.org/browser/transposh-translation-filter-for-wordpress/trunk/transposh.php?rev=2682425#L1989Patch, Third Party Advisory
- https://www.exploitalert.com/view-details.html?id=38891Exploit, Third Party Advisory
- https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/Exploit, Third Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/223373fc-9d78-47f0-b283-109f8e00b802?source=cveThird Party Advisory
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2461Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.