{"id":"CVE-2023-2745","details":"WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.","aliases":["BIT-wordpress-2023-2745","BIT-wordpress-multisite-2023-2745"],"modified":"2026-02-12T00:54:08.571688Z","published":"2023-05-17T09:15:10.303Z","references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/06/msg00024.html"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/52274"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/172426/WordPress-Core-6.2-XSS-CSRF-Directory-Traversal.html"},{"type":"ADVISORY","url":"https://wordpress.org/news/2023/05/wordpress-6-2-1-maintenance-security-release/"},{"type":"ADVISORY","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/edcf46b6-368e-49c0-b2c3-99bf6e2d358f?source=cve"},{"type":"FIX","url":"https://core.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=55765%40%2F&new=55765%40%2F&sfp_email=&sfph_mail="}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wordpress/wordpress","events":[{"introduced":"0"},{"fixed":"206b164e27d3db60ddf5c0b5562b9f92e4fc6fe6"},{"introduced":"058f9903676a7efaee534a682df0a2a8b87574d8"},{"fixed":"61abfb66115c809782419ab4d5f491a62e08e345"},{"introduced":"06fa4161aa74619239cf27017d124081c825684a"},{"fixed":"7e6cddf8dd03933e0f0f5b44b6c89bec3843e4c7"},{"introduced":"14247ee4302378d292863865c643abe99bbfe3c7"},{"fixed":"eb5a504bda5fac38796af50725e7f923bc1ad02e"},{"introduced":"29ffbff370968ae48a1b7a34e35c8b8e75cf0f91"},{"fixed":"dde4da7b797c6f3184834075f3c472a530fe03dd"},{"introduced":"491c67be12ca8a9fe37ae38307ba7e298c976ec3"},{"fixed":"0cac57854d9be31fae947b1ac07e9a6075974264"},{"introduced":"50caeb6e61ad0c49d2c7e1d6d5115047a011f590"},{"fixed":"61d5032484ddbbd548b45f293245b3dc0e791ceb"},{"introduced":"50dc0ca5bb332c895f0f39fe4e6ee1e4a43e06dc"},{"fixed":"18a1be2684e0cbd8c7ebebecfb9ca29b13d7d607"},{"introduced":"537fd931bc02e6e934a2d774422b897871aa87ad"},{"fixed":"efb471e7258d930659983062c5759fcbcab01867"},{"introduced":"6c5d5b5dcb9712bfc400b09cb6627e42898527af"},{"fixed":"ece2b5f087bc93a3ee4047589652d8e4756f8f15"},{"introduced":"6fe64752be3260f2a47f38e68c2cb77400e5a0c9"},{"fixed":"95b6583c2bca8bfbbc0067f938057c60b2578b58"},{"introduced":"73157386d069425c5e6ea7c4fc0122e8a9b58a7b"},{"fixed":"21e34a51aa55a33ca92a24442744ba8c42bc1c48"},{"introduced":"87bf150016e042bc3e21f2f1cb9de44042b8cdb1"},{"fixed":"85ae754b8902916c967ccee1d8040e0fb51cdd8f"},{"introduced":"965fcddcf68cf4fd122ae24b992e242dfea1d773"},{"fixed":"2876d269e6e74858e82dac0bea7cd86ea5a870ec"},{"introduced":"9ff4499281663b0c772787fd4a60538288f842e9"},{"fixed":"64da002d598dda6b682cb595bb317008253695b8"},{"introduced":"b57f3aa5f00a127f209eff74b78787dd3fd5ed4d"},{"fixed":"02242f4554cbdaa345b4545eb0adad7179f1663f"},{"introduced":"c33464a4554cff8a082bc353d9226d8104b80d2b"},{"fixed":"e6664bb77aa10b2fde05fe5d9b0631d43656c7b6"},{"introduced":"cc101b64012b16d087780657a2b828ccd7794a63"},{"fixed":"527210254519f3f5792ac4a2297d57b981cbfd32"},{"introduced":"e3aafee3f2bc07e09bf79389f20ea3db731466c3"},{"fixed":"c129defefef81abe776424ddf459f3b04b7338db"},{"introduced":"f6a29831c76d2dbe82e9ae673539f910654c58a4"},{"fixed":"2e33df0588ff16f2f932717eddd35804efb8bc85"},{"introduced":"fe47e6139dbfc0f0c9ce0d79da77926b5fceaa77"},{"fixed":"c12fc446e7d264326cdd77b62d66f3b7ba99379d"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-2745.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/wordpress/wordpress-develop","events":[{"introduced":"1c0a2efa5eac05dfd3b7d2b9cfe68e02da55b966"},{"fixed":"9403a3e285a7d3743d876765b18dd93e81ba2c69"},{"introduced":"1cf3888655c0eb8b0b0539834ad67db5920190d7"},{"fixed":"8fc4b865610d0342c10a7c55f0e137995d37f2a3"},{"introduced":"2ac9b801ef5c18accf223b093529dacfcf809133"},{"fixed":"b6bf7e716ffb914620302a5bc0e988a1e69aff5e"},{"introduced":"31f7ece8503f0dc6ef1df2473ae3f3d352973e12"},{"fixed":"a1f53bae066d6df3e661a5b345be046752f0d313"},{"introduced":"4b54a6c2c9a3be775cc6dda66ed207998b068c8f"},{"fixed":"44171ce3d4b8ad4123606240c002d93cc16eb2f3"},{"introduced":"5aa596fee9bf6ea7f0ccc2ed51b16c0f2f04076b"},{"fixed":"ba8f29e71e43dc46b6ea6be55384f3ffa64917f2"},{"introduced":"7acf453090c10537e6f41fc4cf2608d7bbcce8ca"},{"fixed":"5231e3557e490141da093d80931cbddef86d70f6"},{"introduced":"7b07c0ccc7453ce057e009ffa65f12a02ce7d2ee"},{"fixed":"7b941f875af101dba779c9a70cf5e48fed422577"},{"introduced":"7c76a1b79e21176b176b5b6d6b03151f8eea4b55"},{"fixed":"a5dacdaf8ce43992be538bfe6421558bf8ac0c6a"},{"introduced":"895d6a691d7ccdfe80cdf999bc0c8a78d11ad55a"},{"fixed":"30f111dd26bb3b34b66abea220065462180ab33c"},{"introduced":"944a787b8071d3a27f4ac68980c21ed6137db91d"},{"fixed":"7a09b68d1a7b452beb22e377d07ad4ad02408dc9"},{"introduced":"96a6969aab5f0b9362cbc984af230bdfc93022e8"},{"fixed":"e42312d0a73359395d22131d61c4a1caf97d99e0"},{"introduced":"b3bf6266acd61682bc654845f621b4426645e324"},{"fixed":"eb65583c140b8c44e2ec040b3778b6291a6fd41c"},{"introduced":"b5f6ca5af6e29fe5df7a65d512b177fa465cfa2e"},{"fixed":"8b7a907fc8c753e2546b06d9ef5e30d9f2ffefa4"},{"introduced":"b83a8be65054cd890e24c7c1416ebbb39aeb4c09"},{"fixed":"7942636324b53f585319bfd9cbea7c27b3572358"},{"introduced":"d05f0a86b23e37b9d97acd9317ff3fd661d64dea"},{"fixed":"c6ad96c4114c1109bcd6729ebc7f942df9c2c07d"},{"introduced":"e0bedd676512ace4c5586337c072037298315f79"},{"fixed":"d3cd96d0a7b4bf5033ab961fe1511d41069ccc91"},{"introduced":"e33c9f3203961a823ec8410fc1481f6c87b4e3db"},{"fixed":"885ff744c56287133a4cbeff9ae61a1b00ab1f9c"},{"introduced":"ec8826ed50f8ce0eea39900eeeba09a9d621f00e"},{"fixed":"c353b6e5b24f7c3f19a856692b9727bd15411197"},{"introduced":"efa83f48bd4ebd066e5efc94b9feefe50e7925a2"},{"fixed":"bbdcbcfb6604a39adf28abe86be2905a3b508c88"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-2745.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}