MEDIUM
Theme and plugin translation for Polylang <= 3.2.16 - Missing Authorization
Published Nov 28, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.72%
Description
The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.2.16 due to missing capability checks in the process_polylang_theme_translation_wp_loaded() function. This makes it possible for unauthenticated attackers to update plugin and theme translation settings and to import translation strings.
Affected products
-
Affected
- ≥ 0, ≤ 3.2.16
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Marcinkazmierski | Theme and plugin translation for Polylang (TTfP) | unaffected | Affected
|
- Theme and Plugin Translation for Polylang Project / Theme and Plugin Translation for Polylang Application< 3.2.17
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51530 Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2814605%40theme-translation-for-polylang%2Ftrunk&old=2812254%40theme-translation-for-polylang%2Ftrunk&sfp_email=&sfph_mail= PatchThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9f6a358a-333c-4eb7-9149-348bf3713943?source=cve
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-4169 Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Nov 28, 2022
Updated Apr 8, 2026
Reserved Nov 28, 2022
Link CVE-2022-4169
CISA Vulnrichment
Updated Feb 7, 2025
Red Hat
No data
GitHub
No data