Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Saggre

#29578of 53,624
8.8Total CVSS
Vulnerabilities · 1
PT-2022-22441
8.8
2022-11-07
WordPress · Loco Translate · CVE-2022-3494
**Name of the Vulnerable Software and Affected Versions** Complianz WordPress plugin versions prior to 6.3.4 Complianz Premium WordPress plugin versions prior to 6.3.6 **Description** The issue allows translators to inject arbitrary SQL through an unsanitized translation. This can be done through an infected translation file or by a user with a translator role using translation plugins such as Loco Translate or WPML. **Recommendations** For Complianz WordPress plugin versions prior to 6.3.4, update to version 6.3.4 or later. For Complianz Premium WordPress plugin versions prior to 6.3.6, update to version 6.3.6 or later. As a temporary workaround, consider restricting the translator role and limiting access to translation plugins until the issue is resolved.