Security Advisory

CVE-2023-2745

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-05-17 08:36:44
Last updated 2026-04-08 17:31:40
Assigner Wordfence
State PUBLISHED

Description

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.