icon

We found results for “

CVE-2023-2745

Good to know:

icon

Date: May 17, 2023

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Path Traversal

CWE-22

Top Fix

icon

Upgrade Version

Upgrade to version 4.1.38,4.2.35,4.3.31,4.4.30,4.5.29,4.6.26,4.7.26,4.8.22,4.9.23,5.0.19,5.1.16,5.2.18,5.3.15,5.4.13,5.5.12,5.6.11,5.7.9,5.8.7,5.9.6,6.0.4,6.1.2,6.2.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us