CVE-2022-45072, CVE-2022-45071
The WPML Multilingual CMS plugin version 4.5.13 and earlier contains a CSRF vulnerability that permits attackers to modify translation job statuses. Although the plugin developers initially addressed a broken access control issue by implementing an authorization check, this fix proved insufficient as the endpoint remained vulnerable to cross-site request forgery attacks. Users with subscriber-level access or higher can have their sessions exploited to alter plugin settings without their knowledge. Version 4.5.14 and later address this flaw.
Based on public CVE data (MITRE/NVD).