Themes Vulnerabilities

Theme and plugin translation for Polylang < 3.2.17 - Unauthenticated Translation Settings Update

Description

The theme does not have authorisation in the process_polylang_theme_translation_wp_loaded() function, which could allow unauthenticated attack to update translation settings, as well as import arbitrary translations

Affects Themes

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Florent BESNARD
Verified
No

Timeline

Publicly Published
2022-11-28 (about 3 years ago)
Added
2022-11-28 (about 3 years ago)
Last Updated
2022-11-28 (about 3 years ago)

Other