CVE · Medium

CVE-2022-45071 — WPML [sitepress-multilingual-cms] < 4.5.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45072, CVE-2022-45071 WPML [sitepress-multilingual-cms] < 4.5.14 Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.5.14 4.5.14 2022-11-09

CVE-2022-45072, CVE-2022-45071

The WPML Multilingual CMS plugin through version 4.5.13 contains a cross-site request forgery vulnerability that allows attackers to change the status of translation jobs without proper authorization. The vulnerability stems from an incomplete security patch that added only basic authorization checks while failing to implement proper CSRF protections. An attacker can exploit this weakness by tricking authenticated users into performing unwanted actions that modify translation job statuses. No patched version has been released to address this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.