CVE-2022-3494
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.
- Affected products
- Complianz, Complianz Premium, Loco Translate, Wpml
- Really-simple-plugins Complianz
- < 6.3.4, 6.3.6
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.3% (69th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2022-11-07
CVE-2022-3494 at NVD
1 known exploit for CVE-2022-3494
Proof-of-concept code and exploit modules indexed by Sploitus