PT-2022-26027 · WordPress · Polylang
Florent Besnard
·
Published
2022-11-28
·
Updated
2022-12-01
·
CVE-2022-4169
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Polylang versions up to, and including, 3.2.16
Description
The Theme and plugin translation for Polylang is vulnerable to authorization bypass due to missing capability checks in the
process polylang theme translation wp loaded() function. This makes it possible for unauthenticated attackers to update plugin and theme translation settings and to import translation strings.Recommendations
For Polylang versions up to, and including, 3.2.16, update to a version higher than 3.2.16 to resolve the issue. As a temporary workaround, consider disabling the
process polylang theme translation wp loaded() function until a patch is available.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Polylang