CVE-2022-45072, CVE-2022-45071
The WPML Multilingual CMS plugin through version 4.5.13 contains a cross-site request forgery vulnerability that allows attackers to change the status of translation jobs without proper authorization. The vulnerability stems from an incomplete security patch that added only basic authorization checks while failing to implement proper CSRF protections. An attacker can exploit this weakness by tricking authenticated users into performing unwanted actions that modify translation job statuses. No patched version has been released to address this issue.
Based on public CVE data (MITRE/NVD).