VulnerabilityModified
CVE-2022-3691
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
HIGH 7.5EPSS 0.87%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.87%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-552
- Affected
- fluenx/deepl pro api translation
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/4248a0af-1b7e-4e29-8129-3f40c1d0c560Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/4248a0af-1b7e-4e29-8129-3f40c1d0c560Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.