WordPress · Loco Translate · CVE-2022-3494
**Name of the Vulnerable Software and Affected Versions**
Complianz WordPress plugin versions prior to 6.3.4
Complianz Premium WordPress plugin versions prior to 6.3.6
**Description**
The issue allows translators to inject arbitrary SQL through an unsanitized translation. This can be done through an infected translation file or by a user with a translator role using translation plugins such as Loco Translate or WPML.
**Recommendations**
For Complianz WordPress plugin versions prior to 6.3.4, update to version 6.3.4 or later.
For Complianz Premium WordPress plugin versions prior to 6.3.6, update to version 6.3.6 or later.
As a temporary workaround, consider restricting the translator role and limiting access to translation plugins until the issue is resolved.