CVE Database /
CVE-2022-3141
CVE · High
CVE-2022-3141 — TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.3.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3141
|
TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.3.3 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.8
|
< 2.3.3
|
2.3.3 |
2022-07-23 |
—
|
CVE-2022-3141
The TranslatePress plugin through version 2.3.2 contains an authenticated SQL injection vulnerability that allows attackers to inject malicious SQL code when adding a new language through the settings page. The flaw stems from inadequate sanitization of user input and improper parameterization of database queries, enabling attackers to bypass backtick escaping using specially crafted characters. Unauthenticated attackers can exploit this vulnerability to append unauthorized SQL commands and retrieve sensitive data from the database. The vulnerability was patched in version 2.3.3.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings