CVE-2025-53485

HIGH

MediaWiki - SecurePoll <1.39.13-1.42.7-1.43.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
Wikimedia Foundation/Mediawiki - SecurePoll extension 1.39.x - 1.39.13
Wikimedia Foundation/Mediawiki - SecurePoll extension 1.42.x - 1.42.7
Wikimedia Foundation/Mediawiki - SecurePoll extension 1.43.x - 1.43.2
Published Jul 04, 2025
Tracked Since Feb 18, 2026