Transposh
Transposh Wordpress Translation: vulnerabilidades y CVE
Transposh Wordpress Translation tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-2536 | Alta (7.5) | 1.4% | — | 15 dic 2022 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of… |
| CVE-2022-2462 | Media (5.3) | 3.7% | — | 6 sept 2022 | The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions… |
| CVE-2022-2461 | Media (5.3) | 4.8% | — | 6 sept 2022 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking… |
| CVE-2022-25812 | Alta (7.2) | 1.7% | — | 22 ago 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE |
| CVE-2022-25811 | Alta (7.2) | 1.4% | — | 22 ago 2022 | The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection |
| CVE-2022-25810 | Media (6.5) | 1.0% | — | 22 ago 2022 | The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the… |
| CVE-2021-24912 | Media (5.4) | 0.34% | — | 22 ago 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of… |
| CVE-2021-24911 | Media (5.4) | 0.67% | — | 22 ago 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the… |
| CVE-2021-24910 | Media (6.1) | 1.6% | — | 22 ago 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is… |