CVE-2022-2461
Transposh WordPress Translation <= 1.0.9.6 - Unauthorized Settings Change
Record summary
CVE-2022-2461 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 25, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Transposh WordPress TranslationBrowse oferwald / Transposh WordPress TranslationDefault status: unaffected | CVE List | Through 1.0.9.6 | affected |
transposh_wordpress_translationBrowse transposh / transposh_wordpress_translation | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMTransposh WordPress Translation <= 1.0.8 - Unauthenticated Settings ChangeCVSS 5.3
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.8.1. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.
Impact
Unauthenticated attackers can modify plugin settings through the tp_translation AJAX endpoint without authentication, potentially manipulating translated content and injecting malicious data that affects all site visitors.
Remediation
Update Transposh WordPress Translation plugin to a version newer than 1.0.8.1 that implements proper authentication checks on AJAX actions.
Source: ProjectDiscovery