CVE-2023-0832, CVE-2023-0831
The Under Construction plugin for WordPress through version 3.96 contains a CSRF vulnerability affecting the install_weglot function, which is triggered by the admin_action_install_weglot action and lacks proper nonce verification. An unauthenticated attacker could exploit this flaw by crafting a malicious request that, if clicked by an administrator, would install the Weglot Translate plugin without authorization. The vulnerability requires social engineering to trick an admin user into following a crafted link.
Based on public CVE data (MITRE/NVD).