My WP Translate <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
high
The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_import_strings() function in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level a...
- CVSS:
- 8.8
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 10, 2025
CVE-2025-8425 on NVD →
My WP Translate <= 1.1 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Option Read and Deletion
medium
The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_code() functions in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 5.4
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 10, 2025
CVE-2025-8423 on NVD →
My WP Translate [my-wp-translate] < 1.0.4 (closed)
unknown
[en] The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Aug 20, 2019
CVE-2017-18568 on NVD →
My WP Translate [my-wp-translate] < 1.0.4 (closed)
unknown
[en] The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Aug 20, 2019
CVE-2017-18569 on NVD →
My WP Translate [my-wp-translate] < 1.0.4 (closed)
unknown
WordPress My WP Translate plugin Authenticated Option Deletion Vulnerability was found in 1.0.3 version and exists in the function ajax_mtswpt_remove_plugin() accessible through WordPress AJAX functionality to users who are logged in.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Oct 11, 2017
My WP Translate <= 1.0.3 - Reflected Cross-Site Scripting
medium
The My WP Translate plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on the 'tab' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browse...
- CVSS:
- 6.1
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Oct 10, 2017
CVE-2017-18568 on NVD →
My WP Translate <= 1.0.3 - Unprotected AJAX Actions
high
The My WP Translate plugin for WordPress is vulnerable to an authorization bypass weakness in versions up to, and including, 1.0.3. This is due to missing capability checks and nonce validation on the following functions: ajax_translation_panel(), ajax_save_translation(), ajax_add_plugin(), ajax_remove_plugin(), ajax_s...
- CVSS:
- 8
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Oct 9, 2017
CVE-2017-18569 on NVD →
My WP Translate [my-wp-translate] <= 1.1 (unfixed)
unknown
- Affected:
- up to 1.1
- Fix:
- No patched version reported
CVE-2025-8425 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database