CVE-2022-25812

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:transposh:transposh_wordpress_translation:*:*:*:*:*:wordpress:*:*

History

25 Aug 2022, 02:42

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/1f6bd346-4743-44b8-86d7-4fbe09bad657 - (MISC) https://wpscan.com/vulnerability/1f6bd346-4743-44b8-86d7-4fbe09bad657 - Exploit, Third Party Advisory
CPE cpe:2.3:a:transposh:transposh_wordpress_translation:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

22 Aug 2022, 16:35

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-22 15:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-25812

Mitre link : CVE-2022-25812

CVE.ORG link : CVE-2022-25812


JSON object : View

Products Affected

transposh

  • transposh_wordpress_translation
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')