PT-2022-24630 · WordPress · Wpml Multilingual Cms

Dave Jong

·

Published

2022-11-18

·

Updated

2022-11-21

·

CVE-2022-38974

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPML Multilingual CMS premium plugin versions <= 4.5.10
Description The issue allows users with subscriber or higher user roles to change the status of the translation jobs due to a Broken Access Control vulnerability in the WPML Multilingual CMS premium plugin on WordPress.
Recommendations For WPML Multilingual CMS premium plugin versions <= 4.5.10, update to a version higher than 4.5.10 to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-38974

Affected Products

Wpml Multilingual Cms