Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-2461 Details

Description

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://packetstormsecurity.com/files/167870/wptransposh107-auth.txt CVEExploitThird Party AdvisoryVDB Entry
https://plugins.trac.wordpress.org/browser/transposh-translation-filter-for-wordpress/trunk/transposh.php?rev=2682425#L1989 CVEPatchThird Party Advisory
https://www.exploitalert.com/view-details.html?id=38891 CVEExploitThird Party Advisory
https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/ CVEExploitThird Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/223373fc-9d78-47f0-b283-109f8e00b802?source=cve CVEThird Party Advisory

see all 12 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-862Missing AuthorizationCISA-ADP
CWE-862Missing Authorization[email protected]
CWE-862Missing Authorization[email protected]

Affected Products

ProductVersions
transposh transposh wordpress translation
<= 1.0.8.1

CPE

  • cpe:2.3:a:transposh:transposh_wordpress_translation:*:*:*:*:*:wordpress:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-2461
NVD Published Date:
Sep 6, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-2461 Details - Not Deferred