S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Sep 16, 2025

CVE-2022-2461 Scanner

CVE-2022-2461 Scanner - Missing Authorization vulnerability in Transposh WordPress Translation

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2461
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Transposh WordPress Translationby oferwald
0
Updated Aug 22, 2026View on NVD →
Detail

The Transposh WordPress Translation plugin is widely used by website owners to automatically translate website content into different languages. It is integrated into WordPress, which is a highly popular content management system for creating and managing websites. The plugin aids in reaching a broader audience by catering to different language speakers across the globe. It is mostly used by bloggers, small businesses, and others who aim to have a multi-language online presence. The plugin simplifies the process of content translation and supports seamless integration within the WordPress environment. It is designed to enhance the user experience by offering language switching capabilities on the website.

The vulnerability relates to the Missing Authorization issue in the Transposh WordPress Translation plugin. When exploited, unauthorized users are able to alter plugin settings without approval, as the plugin fails to adequately check permission on certain actions. This vulnerability affects versions up to 1.0.8, where default settings and insufficient permission checking are present. It allows attackers to influence sensitive settings and potentially manipulate displayed data. The issue involves the 'tp_translation' AJAX action being improperly secured, leading to potential unauthorized changes.

Technically, the vulnerability exists due to inadequate permission checks on the 'tp_translation' AJAX action in the plugin. This endpoint allows unauthenticated users to perform unauthorized settings changes, exploiting the lack of sufficient security measures. The parameters involved such as 'ln0', 'sr0', 'items', and others can be manipulated to change plugin settings through crafted requests. The plugin listens to requests sent to '/wp-admin/admin-ajax.php', where these settings changes are triggered. This exploitation could lead to further unexpected behaviors on the WordPress site using the plugin.

If exploited, the vulnerability can allow malicious users to make unauthorized changes to website translations and settings. This can result in altered content presentation and may lead to false information being displayed to users. Site integrity and trust could be compromised, and unauthorized settings could disrupt normal website operations. Depending on the extent of the manipulation, this could further affect SEO and visitor engagement negatively. Ultimately, the site's reputation and effectiveness in reaching its audience could suffer, requiring swift action to mitigate any unauthorized changes.

REFERENCES

Solution Advice
  • Update the Transposh WordPress Translation plugin to the latest version to patch the vulnerability.
  • Regularly audit plugin permissions and settings to ensure that unauthorized changes cannot be made.
  • Implement strong user authentication and authorization mechanisms to control access to sensitive operations.
  • Consider using a Web Application Firewall (WAF) to detect and block unauthorized requests.
  • Regularly back up site data and configurations to restore them in the event of unauthorized changes.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-2461 Scanner - Missing Authorization vulnerability in Transposh WordPress Translation | S4E