CVE-2025-8425High· 8.8▾ TwilightThe My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_import_strings() function in all versions up to, and includin…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_import_strings() function in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-69220High· 7.1LibreChat is a ChatGPT clone with additional features
CVE-2025-69221Medium· 4.3LibreChat is a ChatGPT clone with additional features
CVE-2025-12925High· 7.3A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
CVE-2025-48614Medium· 4.6In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check
CVE-2025-48604Medium· 5.5In multiple locations, there is a possible way to read files from another user due to a missing permission check
CVE-2025-48599High· 7.8In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check