CVE-2023-0832, CVE-2023-0831
The Under Construction plugin for WordPress through version 3.96 contains a Cross-Site Request Forgery vulnerability in the install_weglot function, which lacks proper nonce verification. An unauthenticated attacker could exploit this flaw to install the Weglot Translate plugin without authorization if they convince a site administrator to click a malicious link. The vulnerability affects the admin_action_install_weglot action handler and was fixed in version 3.97.
Based on public CVE data (MITRE/NVD).