CVE · High

CVE-2022-3141 — TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.3.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3141 TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.3.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 2.3.3 2.3.3 2022-07-23

CVE-2022-3141

The TranslatePress plugin through version 2.3.2 contains an authenticated SQL injection vulnerability that allows attackers to inject malicious SQL code when adding a new language through the settings page. The flaw stems from inadequate sanitization of user input and improper parameterization of database queries, enabling attackers to bypass backtick escaping using specially crafted characters. Unauthenticated attackers can exploit this vulnerability to append unauthorized SQL commands and retrieve sensitive data from the database. The vulnerability was patched in version 2.3.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.