CVE-2023-2745: WordPress
Medium severity, CVSS 5.4. EPSS: 79.5% chance of exploitation in the next 30 days.
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.
Affected products
- WordPress WordPress: before 4.1.38 (fixed in 4.1.38); from 4.2, before 4.2.35 (fixed in 4.2.35); from 4.3, before 4.3.31 (fixed in 4.3.31); from 4.4, before 4.4.30 (fixed in 4.4.30); from 4.5, before 4.5.29 (fixed in 4.5.29); from 4.6, before 4.6.26 (fixed in 4.6.26); …
Published 2023-05-17. Last modified 2026-06-17.