PT-2022-17536 · WordPress · Transposh Wordpress Translation Plugin

Julien Ahrens

·

Published

2022-07-28

·

Updated

2022-08-25

·

CVE-2022-25811

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Transposh WordPress Translation plugin versions 1.0.8 and earlier
Description The issue arises from the plugin's failure to properly sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection. This allows for potential manipulation of database queries.
Recommendations For Transposh WordPress Translation plugin versions 1.0.8 and earlier, update to a version later than 1.0.8 to resolve the issue. As a temporary workaround, consider restricting access to the tp editor module to minimize the risk of exploitation. Avoid using the order and orderby parameters in affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25811

Affected Products

Transposh Wordpress Translation Plugin