4.3
CVSSv3

CVE-2022-38461

Published: 17/11/2022 Updated: 21/07/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpml wpml