PT-2022-17537 · WordPress · Transposh Wordpress Translation Plugin
Julien Ahrens
·
Published
2022-07-29
·
Updated
2022-08-25
·
CVE-2022-25812
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Transposh WordPress Translation plugin versions prior to 1.0.8
Description
The issue is related to the Transposh WordPress Translation plugin, which does not validate its debug settings. This could allow high privilege users, such as admins, to perform remote code execution (RCE).
Recommendations
For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the debug settings to minimize the risk of exploitation.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Transposh Wordpress Translation Plugin