Transposh WordPress Translation 1.0.8.1 Information Disclosure

Discussion in 'News Aggregator' started by Packet Storm, 30 Jul 2022.

  1. Packet Storm

    Packet Storm Guest

    Transposh WordPress Translation versions 1.0.8.1 and below have an ajax action called "tp_history" which is intended to return data about who has translated a text given by the "token" parameter. However, the plugin also returns the user's login name as part of the "user_login" attribute. Successful exploits can allow an unauthenticated attacker to leak the WordPress username of translators. If an anonymous user submitted the translation, then the user's IP address is returned.

    Continue reading...
     

Share This Page

Loading...