High severity7.5NVD Advisory· Published Jul 4, 2025· Updated Apr 15, 2026
CVE-2025-53485
CVE-2025-53485
Description
SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing.
This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Affected products
1- Range: >=1.39.0,<1.39.13,>=1.42.0,<1.42.7,>=1.43.0,<1.43.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.