5.3

CVE-2022-2462

Exploit

Transposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure

Transposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure

The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the response. This makes it possible for unauthenticated users to exfiltrate usernames of individuals who have translated text.
Mögliche Gegenmaßnahme
Transposh WordPress Translation: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TransposhTransposh Wordpress Translation SwPlatformwordpress Version <= 1.0.8.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Transposh WordPress Translation
Version *-1.0.9.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.94% 0.853
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
security@wordfence.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/
Third Party Advisory
Exploit
https://packetstormsecurity.com/files/167878/wptransposh1081-disclose.txt
Third Party Advisory
Exploit
VDB Entry
https://plugins.trac.wordpress.org/browser/transposh-translation-filter-for-wordpress/trunk/transposh.php?rev=2682425#L1948
Patch
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/bd1f12ac-86ac-4be9-9575-98381c3b4291?source=cve
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2462
Third Party Advisory
Exploit
https://github.com/oferwald/transposh/blob/master/transposh.php#L1550
https://www.wordfence.com/threat-intel/vulnerabilities/id/bd1f12ac-86ac-4be9-9575-98381c3b4291
Third Party Advisory