#VU69682 Improper access control in WPML Multilingual CMS - CVE-2022-38461
Published: November 29, 2022
WPML Multilingual CMS
OnTheGoSystems
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and change plugin settings (selected language for legacy widgets, the default behavior for media content).