CVE-2022-38974: WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability
Published Nov 18, 2022
·Updated
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.
Affected Software
1 affected component
WPML Wpml Wordpress<=4.5.10
Remediation
Information
Update to 4.5.11 or higher version.
Event History
Nov 18, 2022
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-38974.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress'.
3
What is the severity of CVE-2022-38974?
The severity of CVE-2022-38974 is medium with a severity value of 4.3.
4
What software is affected by CVE-2022-38974?
The WPML Multilingual CMS premium plugin version up to and including 4.5.10 on WordPress is affected by CVE-2022-38974.
5
How does CVE-2022-38974 affect users?
CVE-2022-38974 allows users with subscriber or higher user roles to change the status of translation jobs.