CVE-2022-2461
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.
- Affected products
- Transposh Wordpress Translation Plugin
- Transposh Transposh Wordpress Translation
- ≤ 1.0.8.1
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 3.6% (88th percentile)
- Weakness
- CWE-862
- NVD status
- Modified
- Published
- 2022-09-06
CVE-2022-2461 at NVD
5 known exploits for CVE-2022-2461
Proof-of-concept code and exploit modules indexed by Sploitus
Transposh WordPress Translation 1.0.7 Cross Site Scripting Vulnerability
Transposh WordPress Translation 1.0.7 Incorrect Authorization Vulnerability
Transposh WordPress Translation 1.0.7 Cross Site Scripting
Transposh WordPress Translation 1.0.7 Incorrect Authorization
Exploit for Cross-site Scripting in Astaro Security_Gateway_Software