PT-2022-24416 · WordPress · Wpml Multilingual Cms

Dave Jong

·

Published

2022-11-17

·

Updated

2023-07-21

·

CVE-2022-38461

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WPML Multilingual CMS premium plugin versions <= 4.5.10
Description The issue allows users with a subscriber or higher user role to change plugin settings, including the selected language for legacy widgets and the default behavior for media content.
Recommendations For WPML Multilingual CMS premium plugin versions <= 4.5.10, update to a version higher than 4.5.10 to resolve the issue. As a temporary workaround, consider restricting access to plugin settings for users with subscriber or higher roles until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-38461

Affected Products

Wpml Multilingual Cms