Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 - Missing Authorization to Sensitive Information Disclosure

2022-03-07 00:00
Diogo Real

Strategic Overview

Status
Patched in 2.9.9
Affected Version< 2.9.9
CVSS8.8High
CVECVE-2022-0770
View all Translate WordPress with GTranslate vulnerabilities

Vulnerability Overview

The Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 WordPress plugins do not have proper capabilities checks in the /wp-content/plugins/gtranslate/url_addon/gtranslate.php file which writes debug data such as user's cookies in a publicly accessible file when the enable_debug parameter is set to true. This would make it possible for an attacker to steal and administrators cookies if they can successfully trick them into accessing that file with the parameter set.

Technical Analysis

REMEDIATION: Update to version 2.9.9, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C