CVE-2022-25812 is a critical remote code execution (RCE) vulnerability affecting the Transposh WordPress Translation plugin versions prior to 1.0.8. This flaw, rated 7.2 HIGH on the CVSS scale, stems from insufficient validation of debug settings, enabling high-privilege users (e.g., administrators) to execute arbitrary code. While the vulnerability has a high potential impact (C, I, A are High), it requires administrator-level access, and there is currently no public exploit code, Metasploit module, or significant community discussion or media coverage, suggesting it is not being actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.8CPE matchmatch criteria | cpe:2.3:a:transposh:transposh_wordpress_translation:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.