plugin

Simple Admin Language Change Vulnerabilities

4 known security issues reported for the Simple Admin Language Change WordPress plugin. Most recent disclosed May 5, 2021.

1 medium

Running Simple Admin Language Change on your site? Check whether your installed version is affected.

Scan your site free

Simple Admin Language Change <= 2.0.1 - Authorization Bypass

medium

The Simple Admin Language Change plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the salc_change_user_locale function in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the lo...

CVSS:
4.3
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
May 5, 2021

Simple Admin Language Change [simple-admin-language-change] < 2.0.2

unknown

Arbitrary User Locale Change vulnerability discovered by WPScan Team in WordPress Simple Admin Language Change plugin (versions <= 2.0.1).

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
May 5, 2021

Simple Admin Language Change [simple-admin-language-change] < 2.0.2

unknown

The Simple Admin Language Change plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the salc_change_user_locale function in versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the lo...

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
May 5, 2021

Simple Admin Language Change [simple-admin-language-change] < 2.0.2

unknown

The plugin did not have proper capability and CSRF checks in its change_user_locale AJAX action, and was also affected by an IDOR issue, allowing any authenticated user to change the locale of another user. v2.0.1 fixed the authorisation and IDOR but still had an incorrect CSRF logic which was fixed in 2.0.2

Affected:
up to 2.0.2
Fixed in:
2.0.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database