Simple Admin Language Change <= 2.0.1 - Authorization Bypass
medium
The Simple Admin Language Change plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the salc_change_user_locale function in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the lo...
- CVSS:
- 4.3
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- May 5, 2021
Simple Admin Language Change [simple-admin-language-change] < 2.0.2
unknown
Arbitrary User Locale Change vulnerability discovered by WPScan Team in WordPress Simple Admin Language Change plugin (versions <= 2.0.1).
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- May 5, 2021
Simple Admin Language Change [simple-admin-language-change] < 2.0.2
unknown
The Simple Admin Language Change plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the salc_change_user_locale function in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the lo...
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- May 5, 2021
Simple Admin Language Change [simple-admin-language-change] < 2.0.2
unknown
The plugin did not have proper capability and CSRF checks in its change_user_locale AJAX action, and was also affected by an IDOR issue, allowing any authenticated user to change the locale of another user.
v2.0.1 fixed the authorisation and IDOR but still had an incorrect CSRF logic which was fixed in 2.0.2
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database