VYPR
Medium severity5.4NVD Advisory· Published Nov 17, 2022· Updated Jun 17, 2026No known patch

CVE-2022-38461

CVE-2022-38461

Description

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:wpml:wpml:*:*:*:*:*:wordpress:*:*
    Range: <=4.5.10
  • Range: <=4.5.10
  • OnTheGoSystems Ltd./WPML Multilingual CMS (WordPress plugin)v5
    Range: <= 4.5.10

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.