CVE · Medium

CVE-2022-38461 — WPML [sitepress-multilingual-cms] < 4.5.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-38461 WPML [sitepress-multilingual-cms] < 4.5.11 Medium 5.4 < 4.5.11 4.5.11 2022-11-09

CVE-2022-38461

The WPML plugin for WordPress versions 4.5.10 and earlier contains a flaw where authorization checks were not properly implemented on certain user control functions. This vulnerability permits attackers with subscriber-level access to modify plugin configuration settings, including the ability to alter language preferences for legacy widgets and adjust default media content handling.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.