Transposh WordPress Translation...

- AV AC AU C I A
发布: 2022-07-29
修订: 2024-12-11

Transposh WordPress Translation versions 1.0.7 and below suffer from an incorrect authorization vulnerability. When installed, Transposh comes with a set of pre-configured options, one of these is the "Who can translate" setting under the "Settings" tab, which by default allows "Anonymous" users to add translations via the plugin's "tp_translation" ajax action. Successful exploits can allow an unauthenticated attacker to add translations to the WordPress site and thereby influence what is actually shown on the site.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息