← back
CVE-2022-3141

Translatepress Multilinugal < 2.3.3 - Admin+ SQLi

EPSS 3.8%CWE-89
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 3.8%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
19 Sep 2022Published on NVD
25 Mar 2023Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →