CVE-2022-0770 - CVE House
Back to Database
Status published High CVE-2022-0770

Translate WordPress with GTranslate < 2.9.9 - CSRF to Account Takeover

Vulnerability Description

The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0770

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Diogo Real

Affected Vendor

Affected Software

Translate WordPress with GTranslate
Vulnerable Versions:
2.9.9

Timeline

Official Publish: March 28th, 2022
Last Modified: August 2nd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)