Cozmoslabs TranslatePress
cpe:2.3:a:cozmoslabs:translatepress:*:*:*:*:wordpress:*:*
- <= 2.9.6
A deserialization vulnerability allowing object injection has been identified in the Cozmoslabs TranslatePress WordPress plugin, affecting versions through 2.9.6. This vulnerability could lead to various impacts, including code execution, SQL injection, path traversal, and denial-of-service, if exploited within a suitable context.
Exploitation of this vulnerability could allow for PHP object injection, which could be leveraged to execute arbitrary code, inject malicious SQL, traverse file paths inappropriately, cause a denial-of-service, or other impacts, depending on the presence of a suitable PHP object injection chain.
Users of the TranslatePress WordPress plugin should update to version 2.9.7 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.