What the vulnerability does
01Description
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.
Explanation of Vulnerability in Simple Terms
02Summary
The Transposh WordPress Translation plugin through version 1.0.9.6 lacks proper authorization checks on certain functions. An unauthenticated attacker can modify site content or settings without permission. The vulnerability requires only network access and no user interaction. Site administrators should update the plugin immediately to prevent unauthorized changes.
What an attacker can do
03Attacker Capabilities
Modify site content or settings without logging in.
Potential impact on your site
04Site Impact
Your site's content or configuration could be altered by anyone on the internet without your knowledge.
Conditions required to exploit
05Prerequisites
None. The attacker needs only network access to the site.
Key dates
06Disclosure timeline
September 6, 2022
CVE published
April 8, 2026
Record updated