Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Theme and plugin translation for Polylang <= 3.2.16 - Missing Authorization
Vulnerability Description
The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.2.16 due to missing capability checks in the process_polylang_theme_translation_wp_loaded() function. This makes it possible for unauthenticated attackers to update plugin and theme translation settings and to import translation strings.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
授权机制缺失
Vulnerability Title
WordPress theme Download Theme and plugin translation for Polylang 安全漏洞
Vulnerability Description
WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress theme是WordPress的一款主题。 WordPress theme Download Theme and plugin translation for Polylang 3.2.16及以前版本存在安全漏洞,该漏洞源于其process_polylang_theme_translation_wp_loaded()函数缺少功能检查使得未经身份验证的
CVSS Information
N/A
Vulnerability Type
N/A