Vulnerability Description
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gtranslate | Translate Wordpress With Gtranslate | < 2.9.9 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/49abe79c-ab1c-4dbf-824c-8daaac7e079dExploitThird Party Advisory
- https://wpscan.com/vulnerability/49abe79c-ab1c-4dbf-824c-8daaac7e079dExploitThird Party Advisory
FAQ
What is CVE-2022-0770?
CVE-2022-0770 is a vulnerability with a CVSS score of 8.8 (HIGH). The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific pa...
How severe is CVE-2022-0770?
CVE-2022-0770 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0770?
Check the references section above for vendor advisories and patch information. Affected products include: Gtranslate Translate Wordpress With Gtranslate.