What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.
Explanation of Vulnerability in Simple Terms
TranslatePress versions up to 2.9.6 contain a deserialization vulnerability that allows high-privileged users to execute arbitrary code on the site. An attacker with administrator or equivalent access can craft malicious serialized data to trigger unintended PHP execution. This affects the plugin's data handling and requires administrative credentials to exploit.
What an attacker can do
Run arbitrary PHP code on the site with full site privileges.
Potential impact on your site
A compromised admin account can be used to take complete control of your site, modify content, install backdoors, or steal data.
Conditions required to exploit
Attacker must have administrator or high-level user account access to the WordPress site.
Key dates
External resources
Related vulnerabilities