← back
CVE-2022-0770

Translate WordPress with GTranslate < 2.9.9 - CSRF to Account Takeover

EPSS 0.6%CWE-352
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 Mar 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →