PT-2022-20734 · WordPress · Translate Multilingual Sites

Elias Hohl

·

Published

2022-09-19

·

Updated

2023-03-27

·

CVE-2022-3141

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Translate Multilingual sites WordPress plugin versions prior to 2.3.3
Description The issue allows for an authenticated SQL injection. This can be achieved by adding a new language via the settings page, containing specific special characters, which can surpass the backticks in the SQL query and allow a time-based blind payload to be injected.
Recommendations For versions prior to 2.3.3, update to version 2.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings page to minimize the risk of exploitation. Avoid using special characters when adding new languages until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-3141

Affected Products

Translate Multilingual Sites