漏洞描述
TranslatePress WordPress plugin <= 3.3.1 contains a sensitive information exposure caused by the 'trp_get_translations_regular' AJAX action saving password-reset URLs in translation dictionary, letting unauthenticated attackers extract admin password-reset URLs, exploit requires automatic string saving enabled and admin profile locale set to a published secondary language.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。