The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/4248a0af-1b7e-4e29-8129-3f40c1d0c560 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-11-21 03:15
Updated : 2023-01-12 11:41
NVD link : CVE-2022-3691
Mitre link : CVE-2022-3691
JSON object : View
CWE
CWE-552
Files or Directories Accessible to External Parties
Products Affected
fluenx
- deepl_pro_api_translation


