PT-2025-37129 · Mythemeshop+1 · My-Wp-Translate

·

CVE-2025-8423

·

Published

2025-09-10

·

Updated

2025-09-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions My WP Translate versions prior to 1.2
Description Unauthorized modification of data is possible due to a missing capability check in the mtswpt remove plugin() and ajax update export code() functions. Authenticated attackers with Subscriber-level access or higher can read and delete arbitrary WordPress options, potentially leading to a denial of service.
Recommendations Update My WP Translate to version 1.2 or later. As a temporary mitigation, restrict access to the mtswpt remove plugin() and ajax update export code() functions.

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8423

Affected Products

My-Wp-Translate