PT-2025-37143 · Smartcatai+1 · Smartcat Translator For Wpml+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Smartcat Translator for WPML versions prior to 3.1.73
Description
An issue exists where authenticated attackers with Author-level access and above can perform a time-based SQL Injection. This occurs due to insufficient escaping of the user-supplied
orderby parameter and a lack of sufficient preparation of the SQL query, allowing the addition of malicious SQL queries to extract sensitive information from the database.Recommendations
Update Smartcat Translator for WPML to version 3.1.73 or later.
Avoid using the
orderby parameter until the plugin is updated.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartcat Translator For Wpml
Smartcat-Wpml