Description
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).
No analysis available yet.
Remediation
Vendor Solution
Update to 4.5.11 or higher version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-41045 | Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content). |
References
History
Thu, 20 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:07:47.296Z
Reserved: 2022-09-14T00:00:00.000Z
Link: CVE-2022-38461
Updated: 2024-08-03T10:54:03.835Z
Status : Modified
Published: 2022-11-17T22:15:10.393
Modified: 2024-11-21T07:16:31.373
Link: CVE-2022-38461
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD