Sploitus

CVE-2022-2462

3 known exploits for CVE-2022-2462

The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the response. This makes it possible for unauthenticated users to exfiltrate usernames of individuals who have translated text.

Transposh Transposh Wordpress Translation
≤ 1.0.8.1
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
3.0% (86th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2022-09-06
CVE-2022-2462 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2022-2462

Proof-of-concept code and exploit modules indexed by Sploitus