Polylang Theme and plugin translation
cpe:2.3:a:theme_and_plugin_translation_for_polylang_project:theme_and_plugin_translation_for_polylang:*:*:*:*:wordpress:*:*
- <= 3.2.16
A vulnerability allowing authorization bypass has been identified in the WordPress plugin 'Theme and Plugin Translation for Polylang', in versions through 3.2.16. This vulnerability arises from inadequate capability checks in the 'process_polylang_theme_translation_wp_loaded()' function, enabling unauthenticated attackers to modify translation settings and import translation strings.
Exploitation of this vulnerability allows unauthorized users to change plugin and theme translation settings and import translation strings, potentially leading to unauthorized content modification on the site.
Users are advised to update the 'Theme and Plugin Translation for Polylang' plugin to version 3.2.17 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.