The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.3.52. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update and delete translations and expose the administrator email address.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 01 Mar 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Faboba
Faboba falang
CPEs cpe:2.3:a:faboba:falang:*:*:*:*:*:wordpress:*:*
Vendors & Products Faboba
Faboba falang

Thu, 08 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 04:30:00 +0000

Type Values Removed Values Added
Description The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.3.52. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update and delete translations and expose the administrator email address.
Title Falang multilanguage for WordPress <= 1.3.52 - Missing Authorization to Translation Update and Information Exposure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-08T14:09:25.603Z

Reserved: 2024-07-17T22:24:08.308Z

Link: CVE-2024-6869

cve-icon Vulnrichment

Updated: 2024-08-08T14:09:18.364Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-08T05:15:50.473

Modified: 2025-03-01T02:14:17.087

Link: CVE-2024-6869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.