Transposh WordPress Translation <= 1.0.9.6 - Authorization Bypass
Summary
| CVE | CVE-2022-2536 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-15 19:15:17 UTC |
| Updated | 2026-04-08 19:17:52 UTC |
| Description | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of settings on the 'tp_translation' AJAX action which makes it possible for unauthenticated attackers to bypass any restrictions and influence the data shown on the site. Please note this is a separate issue from CVE-2022-2461. Notes from the researcher: When installed Transposh comes with a set of pre-configured options, one of these is the "Who can translate" setting under the "Settings" tab. However, this option is largely ignored, if Transposh has enabled its "autotranslate" feature (it's enabled by default) and the HTTP POST parameter "sr0" is larger than 0. This is caused by a faulty validation in "wp/transposh_db.php." |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.007740000 probability, percentile 0.735840000 (date 2026-04-09)
Problem Types: CWE-285 | CWE-285 CWE-285 Improper Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 3.1 | [email protected] | Primary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Transposh | Transposh Wordpress Translation | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Oferwald | Transposh WordPress Translation | affected 1.0.9.6 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Transposh WordPress Translation 1.0.8.1 Incorrect Authorization ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Vulnerability Advisories Continued - Wordfence | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| Transposh WordPress Translation 1.0.8.1 Incorrect Authorization - Exploitalert | af854a3a-2127-422b-91ae-364da2661108 | www.exploitalert.com | Exploit, Third Party Advisory |
| advisories/CVE-2022-2536.txt at master · MrTuxracer/advisories · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Third Party Advisory |
| www.wordfence.com/threat-intel/vulnerabilities/id/c774b520-9d9f-4102-8564-49673... | [email protected] | www.wordfence.com | |
| WordPress Transposh: Exploiting a Blind SQL Injection via XSS - RCE Security | af854a3a-2127-422b-91ae-364da2661108 | www.rcesecurity.com | Not Applicable |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Exploit, Third Party Advisory |
| Transposh WordPress Translation <= 1.0.8.1 - Authorization Bypass | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Julien Ahrens (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2022-11-14T00:00:00.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.