Impact
ConveyThis conveythis-translate suffers from a missing authorization flaw that lets attackers gain access to management functions that should be protected. The vulnerability is a classic broken access control weakness (CWE‑862) and may allow a remote user to perform privileged actions such as modifying translation settings, viewing sensitive data, or potentially inserting content without permission. The impact is moderate, reflected in the CVSS score of 5.3, and it could compromise the integrity and confidentiality of a WordPress site that uses this plugin.
Affected Systems
WordPress sites running the ConveyThis translate plugin version 269.2 or earlier are affected. No other WordPress core or plugin versions are listed as vulnerable.
Risk and Exploitability
With a CVSS of 5.3 the potential damage is significant but not catastrophic. The EPSS score of less than 1% indicates a very low probability of being actively exploited in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a malicious actor crafting a web request to the plugin’s unprotected endpoint to elevate privileges, as the issue stems from incorrectly configured access control levels within the plugin’s code.
OpenCVE Enrichment