Falang Multilanguage Plugin Vulnerability Affects Translation Data
CVE-2024-6869
7.1HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 8 August 2024
What is CVE-2024-6869?
The Falang Multilanguage Plugin for WordPress contains vulnerabilities that allow authenticated attackers with Subscriber-level access or higher to make unauthorized modifications to data. Due to missing capability checks in several functions, these attackers can alter and delete translations, as well as disclose the email address of the site administrator. This flaw is present in all versions up to and including 1.3.52, posing a risk to site integrity and user privacy.
Affected Version(s)
Falang multilanguage for WordPress * <= 1.3.52