CVE-2022-0770
28.03.2022, 18:15
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page
Vendor | Product | Version |
---|---|---|
gtranslate | translate_wordpress_with_gtranslate | 𝑥 < 2.9.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration