CVE-2022-2462

Source
https://cve.org/CVERecord?id=CVE-2022-2462
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2462.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-2462
Published
2022-09-06T17:18:57Z
Modified
2026-08-12T03:51:08.474586838Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Transposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure
Details

The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the response. This makes it possible for unauthenticated users to exfiltrate usernames of individuals who have translated text.

Database specific
{
    "cna_assigner": "Wordfence",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2462.json",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/oferwald/transposh

Affected ranges

Type
GIT
Repo
https://github.com/oferwald/transposh
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.0.9.6"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.0.9.2
v1.0.9.3
v1.0.9.4
v1.0.9.5
v1.0.9.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2462.json"