CVE-2022-25811
Transposh WordPress Translation <= 1.0.8 - Admin+ SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection
El plugin Transposh WordPress Translation de WordPress versiones hasta 1.0.8, no sanea y escapa de los parámetros order y orderby antes de usarlos en una sentencia SQL, conllevando a una inyección SQL
The Transposh WordPress Translation plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' parameters in versions up to, and including, 1.0.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative level permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Transposh WordPress Translation versions 1.0.8.1 and below have a "tp_editor" page at "/wp-admin/admin.php?page=tp_editor" that is vulnerable to two authenticated, blind SQL injections when user-supplied input to the HTTP GET parameters "order" and "orderby" is processed by the web application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-23 CVE Reserved
- 2022-07-22 CVE Published
- 2024-03-14 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/0e0d2c5f-3396-4a0a-a5c6-6a98de3802c9 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Transposh Search vendor "Transposh" | Transposh Wordpress Translation Search vendor "Transposh" for product "Transposh Wordpress Translation" | <= 1.0.8 Search vendor "Transposh" for product "Transposh Wordpress Translation" and version " <= 1.0.8" | wordpress |
Affected
|