WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability
CVE-2022-38461
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 November 2022
What is CVE-2022-38461?
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).
Affected Version(s)
WPML Multilingual CMS (WordPress plugin) <= 4.5.10 <= 4.5.10