Impact
Wagtail versions earlier than 7.0.8, 7.3.3, and 7.4.2 allow a user who possesses the "Can submit translation" permission to create translations for any page, even when that user lacks edit rights on the the user to produce translated page content in locations they are not authorized to modify, potentially disseminating content incorrectly or bypassing editorial controls.
Affected Systems
The vulnerability affects the Wagtail content management system. Any deployment running a version older than 7.0.8, 7.3.3, or 7.4.2 is at to Wagtail’s page translation functionality accessed via the simple_translation interface.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑medium severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker can select any page in the translation workflow and create a translation without needing additional authorization checks.
OpenCVE Enrichment