Transposh WordPress Translation [transposh-translation-filter-for-wordpress] <= 1.0.8.1 (unfixed + closed)
unknown
[en] The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.8.1. This is due to insufficient validation of settings on the 'tp_translation' AJAX action which makes it possible for unauthenticated attackers to...
- Affected:
- up to 1.0.8.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 15, 2022
CVE-2022-2536 on NVD →
Transposh WordPress Translation <= 1.0.9.6 - Authorization Bypass
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of settings on the 'tp_translation' AJAX action which makes it possible for unauthenticated attackers to bypas...
- CVSS:
- 5.3
- Affected:
- up to 1.0.9.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 14, 2022
CVE-2022-2536 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] <= 1.0.8.1 (closed)
unknown
[en] The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.8.1. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenti...
- Affected:
- up to 1.0.8.1
- Fixed in:
- 1.0.8.1
- Disclosed:
- Sep 6, 2022
CVE-2022-2461 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] <= 1.0.8.1 (closed)
unknown
[en] The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.8.1. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the re...
- Affected:
- up to 1.0.8.1
- Fixed in:
- 1.0.8.1
- Disclosed:
- Sep 6, 2022
CVE-2022-2462 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] < 1.0.9.2
unknown
[en] The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the lowest-privileged user. Basically all Utilities functionalities are vulnerable this way, which...
- Affected:
- up to 1.0.9.2
- Fixed in:
- 1.0.9.2
- Disclosed:
- Aug 22, 2022
CVE-2022-25810 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] <= 1.0.8.1 (unfixed + closed)
unknown
[en] The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection
- Affected:
- up to 1.0.8.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 22, 2022
CVE-2022-25811 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] <= 1.0.8.1 (unfixed + closed)
unknown
[en] The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE
- Affected:
- up to 1.0.8.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 22, 2022
CVE-2022-25812 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] < 1.0.8 (closed)
unknown
[en] The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting iss...
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Aug 22, 2022
CVE-2021-24910 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] < 1.0.8 (closed)
unknown
[en] The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin...
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Aug 22, 2022
CVE-2021-24911 on NVD →
Transposh WordPress Translation [transposh-translation-filter-for-wordpress] <= 1.0.8.1 (unfixed + closed)
unknown
[en] The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which wil...
- Affected:
- up to 1.0.8.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 22, 2022
CVE-2021-24912 on NVD →
Transposh WordPress Translation <= 1.0.9.1 - Remote Code Execution
high
The Transposh WordPress Translation plugin for WordPress is vulnerable to remote code execution in versions up to, and including, 1.0.9.1. This is due to insufficient extension validation on the log file that can be created via the plugin. This makes it possible for authenticated attackers with administrative level per...
- CVSS:
- 7.2
- Affected:
- up to 1.0.9.1
- Fixed in:
- 1.0.9.2
- Disclosed:
- Jul 22, 2022
CVE-2022-25812 on NVD →
Transposh WordPress Translation <= 1.0.7 - Unauthenticated Stored Cross-Site Scripting via 'tp_translation'
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tk0' parameter in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.5
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Jul 22, 2022
CVE-2021-24911 on NVD →
Transposh WordPress Translation <= 1.0.9.1 - Missing Authorization Checks
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions called via AJAX actions in versions up to, and including, 1.0.9.1. This makes it possible for authenticated attackers with subscriber-level permissions and above to perfo...
- CVSS:
- 6.3
- Affected:
- up to 1.0.9.1
- Fixed in:
- 1.0.9.2
- Disclosed:
- Jul 22, 2022
CVE-2022-25810 on NVD →
Transposh WordPress Translation <= 1.0.7 - Reflected Cross-Site Scripting via tp_tp
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Jul 22, 2022
CVE-2021-24910 on NVD →
Transposh WordPress Translation <= 1.0.9.1 - Authenticated (Admin+) SQL Injection via 'tp_editor'
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' parameters in versions up to, and including, 1.0.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...
- CVSS:
- 4.9
- Affected:
- up to 1.0.9.1
- Fixed in:
- 1.0.9.2
- Disclosed:
- Jul 22, 2022
CVE-2022-25811 on NVD →
Transposh WordPress Translation <= 1.0.9.1 - Cross-Site Request Forgery
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.9.1. This is due to missing nonce validation on several AJAX action function. This makes it possible for unauthenticated attackers to performa variety of actions such as initiating...
- CVSS:
- 4.3
- Affected:
- up to 1.0.9.1
- Fixed in:
- 1.0.9.2
- Disclosed:
- Jul 22, 2022
CVE-2021-24912 on NVD →
Transposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the respons...
- CVSS:
- 5.3
- Affected:
- up to 1.0.9.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 18, 2022
CVE-2022-2462 on NVD →
Transposh WordPress Translation <= 1.0.9.6 - Unauthorized Settings Change
medium
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated...
- CVSS:
- 5.3
- Affected:
- up to 1.0.9.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 18, 2022
CVE-2022-2461 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database