← back
CVE-2022-3141CWE-89

Translatepress Multilinugal < 2.3.3 - Admin+ SQLi

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 4.1%
from disclosure to weapon187 days
Published on NVDSep 19
1st PoC+187d
exploitation probability
4.1%top 10% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.