CVE-2023-2745: WordPress Core < 6.2.1 - Directory Traversal
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wplang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-2745.
What is the title of this vulnerability?
The title of this vulnerability is 'WordPress Core is vulnerable to Directory Traversal in versions up to and including 6.2 via the ‘wp_lang’ parameter.'
What is the severity of CVE-2023-2745?
The severity of CVE-2023-2745 is medium (5.4).
How does CVE-2023-2745 impact WordPress?
CVE-2023-2745 allows unauthenticated attackers to access and load arbitrary translation files in WordPress versions up to and including 6.2.
Are there any known fixes for CVE-2023-2745?
At the moment, there are no known fixes for CVE-2023-2745. It is recommended to update to a newer version of WordPress when a fix becomes available.