{"error":0,"message":null,"data":{"name":"WPML","plugin":"sitepress-multilingual-cms","link":"https:\/\/wpml.org\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"8f08fd42aa22449a20eec40837f0d04aa82650dd203ddc812d8ac293158f3144","name":"WPML [sitepress-multilingual-cms] < 4.3.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-10568","name":"CVE-2020-10568","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-10568","description":"[en] The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes\/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.","date":"2020-03-14"},{"id":"0d4765395033c3964f23b34fc52ce4cf2c5bfa12","name":"WordPress WPML plugin <= 4.3.6 - Authenticated Cross-Site Request Forgery (CSRF) vulnerability leading to Remote Code Execution (RCE)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-4-3-6-authenticated-cross-site-request-forgery-csrf-vulnerability-leading-to-remote-code-execution-rce","description":"Authenticated Cross-Site Request Forgery (CSRF) vulnerability leading to Remote Code Execution (RCE) discovered by Gerard Arall in WordPress WPML plugin (versions <= 4.3.6).","date":"2020-03-09"},{"id":"687f8f0aef4c68d62661432fd7b9649d658d3cfd","name":"WPML < 4.3.7 - Cross-Site Request Forgery Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-437-b2-cross-site-request-forgery-bypass","description":"The sitepress-multilingual-cms (WPML) plugin before 4.3.7 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes\/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.","date":"2020-03-09"},{"id":"39638389-722d-4ecf-b87c-5bca2709241b","name":"WPML &lt; 4.3.7 - Authenticated Cross Site Request Forgery leading to Remote Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/39638389-722d-4ecf-b87c-5bca2709241b","description":"The sitepress-multilingual-cms (WPML) WordPress plugin before version 4.3.7 has CSRF due loose comparison, that leads to remote code execution.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"07c61f65b69b6b0f199155103c6532b8438cf866d8b0ba89aa69b4ddc3c60029","name":"WPML [sitepress-multilingual-cms] >= 2.9.3 - <= 3.2.6","description":null,"operator":{"min_version":"2.9.3","min_operator":"ge","max_version":"3.2.6","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9416","name":"CVE-2015-9416","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9416","description":"[en] The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.","date":"2019-09-25"},{"id":"e59a340e8876002e20a43b809f94da1afe2cfc65","name":"WPML 2.9.3-3.2.6 - Cross-Site Scripting in Accept-Language Header","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-293-326-cross-site-scripting-in-accept-language-header","description":"The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.","date":"2015-09-02"},{"id":"769a1ffd-c2d8-42d4-9a89-ea70ca2cde19","name":"WPML 2.9.3-3.2.6 - Cross-Site Scripting (XSS) in Accept-Language Header","link":"https:\/\/wpscan.com\/vulnerability\/769a1ffd-c2d8-42d4-9a89-ea70ca2cde19","description":"The sitepress-multilingual-cms WordPress plugin was affected by a Cross-Site Scripting (XSS) in Accept-Language Header security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"a0d9c8036720c247c297c4c8ecf8993bc638daffb060591234b340f0db32880a","name":"WPML [sitepress-multilingual-cms] < 4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-18069","name":"CVE-2018-18069","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-18069","description":"[en] process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin\/admin.php.","date":"2018-10-08"},{"id":"3d186d79617b578388f5150bf7ed764f739695da","name":"WPML <= 3.6.3 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-363-unauthenticated-stored-cross-site-scripting","description":"process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an unauthenticated theme-localization.php request to wp-admin\/admin.php.","date":"2018-10-08"},{"id":"024b43d3-1e73-47f1-81d2-ab15a6c7b0fd","name":"WPML &lt;= 3.6.3 - Unauthenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/024b43d3-1e73-47f1-81d2-ab15a6c7b0fd","description":"The sitepress-multilingual-cms WordPress plugin was affected by an Unauthenticated Stored Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"6ce8c7a82b40c135216d64dd20b7eb7115cc78c12ae30693a81a1331b4d58c5e","name":"WPML [sitepress-multilingual-cms] < 3.1.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2791","name":"CVE-2015-2791","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2791","description":"[en] The \"menu sync\" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms\/menu\/menus-sync.php.","date":"2015-03-30"},{"id":"73f414289b6e1f825ecbb041424905f45ae1bdea","name":"WordPress WPML Plugin <= 3.1.8 - SQL Injection #1","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-3-1-8-sql-injection","description":"Because of the \"menu sync\" function, remote attackers can delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms\/menu\/menus-sync.php. \r\n\r\nRelated records:\r\n\r\nhttp:\/\/db.threatpress.com\/vulnerability\/wpml---wordpress-multilingual-\/wordpress-wpml-plugin-3-1-8-sql-injection-2\nUpdate the plugin.","date":"2015-03-30"},{"id":"268c3634a3e4ca2cf74b9a4b6e3f0742be1fa1eb","name":"WPML <= 3.1.9 - Arbitrary Deletion of Content","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-319-arbitrary-deletion-of-content","description":"The \"menu sync\" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms\/menu\/menus-sync.php.","date":"2015-03-10"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"}}},{"uuid":"984f0c17d586e3058af392d0b08b1158985a047bac59eb7e2527103fd71cbb0b","name":"WPML [sitepress-multilingual-cms] < 3.1.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2792","name":"CVE-2015-2792","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2792","description":"[en] The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.","date":"2015-03-30"},{"id":"e3f7ca7af321f82bd317ab068ea04ff9b1f3d3f6","name":"WordPress WPML Plugin <= 3.1.8 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-3-1-8-multiple-vulnerabilities","description":"This WordPress Multilingual plugin is prone to SQL injection, missing authentication, page\/post\/menu deletion and reflected XSS vulnerabilities.\nUpdate the plugin.","date":"2015-03-30"},{"id":"dd625f5fe06aae3dc943e59feb1d3bb417dcf5dd","name":"WPML < 3.1.8 - Authorization Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-318-authorization-bypass","description":"The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.","date":"2015-03-02"},{"id":"9b7096ff-af8b-49e4-8f23-4e7e2964d2f5","name":"WPML &lt;= 3.1.7.2 - Multiple Vulnerabilities (Including SQLi)","link":"https:\/\/wpscan.com\/vulnerability\/9b7096ff-af8b-49e4-8f23-4e7e2964d2f5","description":"The sitepress-multilingual-cms WordPress plugin was affected by a Multiple Vulnerabilities (Including SQLi) security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}]}},{"uuid":"ebe5877d96a701e6260e6020623880cdc2e3b15cee77fc82ebf161d148e11e49","name":"WPML [sitepress-multilingual-cms] < 3.1.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2314","name":"CVE-2015-2314","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2314","description":"[en] SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments\/feed.","date":"2015-03-17"},{"id":"1a45dc8a43d9af5bd4a24a51b63ac646f1d39abd","name":"WordPress WPML Plugin <= 3.1.9.1 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-multiple-vulnerabilities","description":"WPML is prone to SQL injection, page or post menu deletion and reflected cross-site scripting vulnerabilities.\nUpdate the plugin.","date":"2015-03-16"},{"id":"52f47c5bd2eee8863983bfcd4eb90ce1a10701a4","name":"WordPress WPML Plugin <= 3.1.8 - SQL Injection #2","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-3-1-8-sql-injection-2","description":"Because of this vulnerability, the attackers can execute arbitrary SQL commands via the \"lang\" parameter in the HTTP Referer header in a wp-link-ajax action to comments\/feed. \r\n\r\nRelated records:\r\n\r\nhttp:\/\/db.threatpress.com\/vulnerability\/wpml---wordpress-multilingual-\/wordpress-wpml-plugin-3-1-8-sql-injection-2\nUpdate the plugin.","date":"2015-03-17"},{"id":"a7d21e12cbbe0ef6a52e75d156cbcadb24aba224","name":"WPML <= 3.1.9 - SQL Injection via lang Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-319-sql-injection-via-lang-parameter","description":"SQL injection vulnerability in the WPML plugin before 3.1.9.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments\/feed.","date":"2015-03-10"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"34aecaedc6241185635a64caa39a4ca272163cce59f36f344a63f56c89a749c8","name":"WPML [sitepress-multilingual-cms] < 3.1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2315","name":"CVE-2015-2315","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2315","description":"[en] Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.","date":"2015-03-17"},{"id":"07f9999a725b1c0f0be6b7b846dad4ac183de42e","name":"WordPress WPML Plugin <= 3.1.8 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-3-1-8-xss","description":"This vulnerability allows an attacker to inject arbitrary web script or HTML via the \"target\" parameter in a reminder_popup action to the default URI.\nUpdate the plugin.","date":"2015-03-17"},{"id":"0530319e7bcb3d8123eebb4134e5f27db37a7e90","name":"WPML < 3.1.9 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpml\/wpml-319-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.","date":"2015-03-11"},{"id":"1e3e4ca5-0472-4302-948c-73d55de3d7d1","name":"Wpml &lt; 3.1.9 - XSS","link":"https:\/\/wpscan.com\/vulnerability\/1e3e4ca5-0472-4302-948c-73d55de3d7d1","description":"The wpml WordPress plugin was affected by a XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"ae868f5a87145115661e53e313c623e9375501e1c45e60a820e908466db2dfaa","name":"WPML [sitepress-multilingual-cms] < 3.1.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"47d352229686864ecc6d2ed1afe44c3716acbcd4","name":"WordPress Multilingual CMS Plugin <= 3.1.7.1 - Full Path Disclosure","link":"https:\/\/patchstack.com\/database\/vulnerability\/sitepress-multilingual-cms-\/wordpress-multilingual-cms-plugin-3-1-7-1-full-path-disclosure","description":"This plugin is prone to a full path disclosure vulnerability.\nUpdate plugin.","date":"2015-10-18"}],"impact":[]},{"uuid":"2037a4baf541ccec6e32b1a50eb1d21a63fdcefc4be6c782495282b1619c2cff","name":"WPML [sitepress-multilingual-cms] < 3.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0129253247d44f37a80aa3c512de61704d694f5a","name":"WordPress WPML Plugin <= 3.2.6 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-3-2-6-cross-site-scripting","description":"This plugin is prone to a cross site scripting vulnerability in accept-language header.\nUpdate the plugin.","date":"2015-09-02"}],"impact":[]},{"uuid":"7a5af04fae7e43890d87eebf8510d8606aa739c534b4f2b13df659f26a23b762","name":"WPML [sitepress-multilingual-cms] < 4.5.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-45071","name":"CVE-2022-45071","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-45071","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.","date":"2022-11-17"},{"id":"377b656493eb69f4a1cca780b0f5c063a4f32b60","name":"WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-wpml-multilingual-cms-premium-plugin-4-5-13-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability discovered by Dave Jong (Patchstack) in WordPress WPML Multilingual CMS premium plugin (versions <= 4.5.13)\nNo patched version is available. Originally reported as a Broken Access Control vulnerability which allowed subscriber or higher role users to change the plugin settings. An insufficient patch was applied, and only an authorization check was added. This vulnerability can still be exploited through the attack CSRF vector.","date":"2022-11-09"},{"id":"fedbeffb363bdd6fd209bf35e3b5d21893ea92f4","name":"WPML <= 4.5.13 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-4513-cross-site-request-forgery","description":"The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to change the plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-11-09"},{"id":"8bf2529a-3fc3-47bb-959a-1f97bd6e4ec1","name":"WPML &lt; 4.5.14 - CSRF","link":"https:\/\/wpscan.com\/vulnerability\/8bf2529a-3fc3-47bb-959a-1f97bd6e4ec1","description":"The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as change the status of a translation job","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0a569bef4655b895ac0781d5d0dac414b10536216faa078de19c88665828824b","name":"WPML [sitepress-multilingual-cms] < 4.5.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-38461","name":"CVE-2022-38461","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-38461","description":"[en] Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).","date":"2022-11-17"},{"id":"d6aac75c1e8ba391b33a5de2180ca61d5bcf7de1","name":"WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-wpml-multilingual-cms-plugin-4-5-10-broken-access-control-vulnerability","description":"Broken Access Control vulnerability leading to plugin settings change (selected language for legacy widgets can be changed, and default behavior for media content can be changed) discovered by Dave Jong in WordPress WPML Multilingual CMS premium plugin (versions <= 4.5.10).\nUpdate the WordPress Multilingual CMS plugin to the latest available version (at least 4.5.11).","date":"2022-11-09"},{"id":"a6f0684207a151eabd1ffb893367ba5859c97d9d","name":"WPML <= 4.5.10 - Missing Authorization to Settings Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-4510-missing-authorization-to-settings-change","description":"The WPML plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 4.5.10. This is due to improper access controls on authorization for user controls. This makes it possible for subscriber-level attackers to perform plugin settings changes.  This means allows the change of the language for legacy widgets, and the default behaviors for media content.","date":"2022-11-09"},{"id":"d4007060-aea1-4e69-bb3c-360cf2ee6e33","name":"WPML &lt; 4.5.11 - Subscriber+ Settings Update","link":"https:\/\/wpscan.com\/vulnerability\/d4007060-aea1-4e69-bb3c-360cf2ee6e33","description":"The plugin does not have authorisation check when updating the selected language for legacy widgets and default behaviour for media content settings, which could allow any authenticated users, such as subscriber to update them","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"1.4"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"17607ba7e13a007aee16eab26784b1c5f7d5fad6c94df190e5f52d8853cf1ed8","name":"WPML [sitepress-multilingual-cms] < 4.5.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-38974","name":"CVE-2022-38974","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-38974","description":"[en] Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.","date":"2022-11-18"},{"id":"1af56a7b1da45f467f94ec04a2d35b4c4cda1b36","name":"WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-wpml-multilingual-cms-plugin-4-5-10-broken-access-control-vulnerability-2","description":"Broken Access Control vulnerability leading to status change of translation job discovered by Dave Jong (Patchstack) in the WordPress WPML Multilingual CMS premium plugin (versions <= 4.5.10).\nUpdate the WordPress Multilingual CMS plugin to the latest available version (at least 4.5.11).","date":"2022-11-09"},{"id":"31c475b340fa0c3be664e628cc57b42429556bf9","name":"WPML <= 4.5.10 - Missing Authorization to Translation Job Status Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-4510-missing-authorization-to-translation-job-status-change","description":"The WPML plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 4.5.10. This is due to improper access controls on authentication for user controls. This makes it possible for subscriber-level attackers to perform status changes of translation jobs.","date":"2022-11-09"},{"id":"d8fcfbf6-6480-4cad-93cd-ae5b08ea9c7b","name":"WPML &lt; 4.5.11 - Subscriber+ Translation Job Status Update","link":"https:\/\/wpscan.com\/vulnerability\/d8fcfbf6-6480-4cad-93cd-ae5b08ea9c7b","description":"The plugin does not have authorisation when updating the status of translation jobs, which could allow any authenticated users, such as subscriber to perform such action","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2d35c40fe4e2ee07a9f4c08fa48a936ee7927b5b9be434542b3088a06bb846ae","name":"WPML [sitepress-multilingual-cms] < 4.5.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-45072","name":"CVE-2022-45072","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-45072","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.","date":"2022-11-17"},{"id":"17956407dbc50e730c47e494426a175626a33602","name":"WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-wpml-multilingual-cms-premium-plugin-4-5-13-cross-site-request-forgery-csrf-vulnerability-2","description":"Cross-Site Request Forgery (CSRF) vulnerability leading to status change of translation job discovered by Dave Jong (Patchstack) in WordPress WPML Multilingual CMS premium plugin (versions <= 4.5.13).\nNo patched version is available. Originally reported as a Broken Access Control vulnerability which allowed subscriber or higher role users to change the plugin settings. An insufficient patch was applied, and only an authorization check was added. This vulnerability can still be exploited through the attack CSRF vector.","date":"2022-11-09"},{"id":"d3586ec81e32847a5984aec16a4b7e2baa6c50b9","name":"WPML  <= 4.5.13 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-4513-cross-site-request-forgery-2","description":"The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unspecified function. This makes it possible for unauthenticated attackers to enact the status change of translation jobs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-11-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e114f0f90e92b8592acb8d1ad9aa83eb913727b4f96332e0bfc51aa3fedc3ff5","name":"WPML [sitepress-multilingual-cms] < 4.5.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6752aac56099b655f02b8c0663feef839938a4eb","name":"WPML <= 4.5.10 - Unprotected AJAX Actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-4510-unprotected-ajax-actions","description":"The WPML plugin for WordPress contains several AJAX actions that fail to perform capability checks or nonce checks. These allow authenticated users to set content defaults, update language settings for legacy widgets, and abort translations.","date":"2022-09-26"}],"impact":[]},{"uuid":"cd44311e22d6cbb50bd292885d85556a19a09eb6cd75c58d0da1b23d1d41e77a","name":"WPML [sitepress-multilingual-cms] < 4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d84dd05cff2ba9d304057748183838be1adfecdd","name":"WordPress  WPML - WordPress Multilingual  Plugin  < 4.6.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpml\/vulnerability\/wordpress-wpml-plugin-4-6-1-cross-site-scripting-xss-vulnerability","description":"Update the WordPress WPML - WordPress Multilingual plugin to the latest available version (at least 4.6.1).\nAn unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WPML - WordPress Multilingual  Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.6.1.","date":"2023-03-16"}],"impact":[]},{"uuid":"fa2f2e2cfa6b1c8c39bfef47bcfa40f7a7da82fc5f7e40a756f5b8e70f0a7023","name":"WPML [sitepress-multilingual-cms] < 4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e9e78e3d6e95791e604802f9ff04f8d6cd09d212","name":"WPML <= 4.6.0 - Reflected Cross-Site Scripting via wp_lang","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-460-reflected-cross-site-scripting-via-wp-lang","description":"The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-04-16"}],"impact":[]},{"uuid":"307a91f4c07f14d2ed1b5610775fc22bb9e5f31651a3d57878ebddf6ec35bb65","name":"WPML [sitepress-multilingual-cms] < 4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"78c61a4d2e5a1799f42963d44d4c679d4a524954","name":"WPML <= 4.6.1 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpml\/wpml-461-cross-site-scripting","description":"The WPML plugin for WordPress is vulnerable to Cross-Site Scripting in versions prior to 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2023-03-16"}],"impact":[]},{"uuid":"226aa65ac1eed9d7a163008f353845978ab53f5ac7d59d30216a78212394e6db","name":"WPML [sitepress-multilingual-cms] < 3.1.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"66055736d7aca21b67f42c0ef939d7508e1cb0a7","name":"WordPress  Multilingual CMS Plugin  <= 3.1.7.1 is vulnerable to Full Path Disclosure (FPD)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-multilingual-cms-plugin-3-1-7-1-full-path-disclosure","description":"Update plugin.\nAn unknown person discovered and reported this Full Path Disclosure (FPD)  vulnerability in WordPress Multilingual CMS Plugin.  This vulnerability has been fixed in version 3.1.7.2.","date":"2023-10-18"}],"impact":[]},{"uuid":"a733118894ca6e76455e4d19e13c8e5a89649fad54f33423ff0f2791b3d40c39","name":"WPML [sitepress-multilingual-cms] < 4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b9cc519c-7ec2-42c3-9f42-01e928e12139","name":"WPML Multilingual CMS &lt; 4.6.1 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/b9cc519c-7ec2-42c3-9f42-01e928e12139","description":"The plugin does not escape some URL attributes before outputting them to a page, leading to a Reflected Cross-Site Scripting vulnerability.","date":null}],"impact":[]},{"uuid":"df5e58b6de2ad6f2829a284a5e5aab4f74599ef3d091ae15e48dd7631ce5f053","name":"WPML [sitepress-multilingual-cms] < 4.6.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6386","name":"CVE-2024-6386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6386","description":"[en] The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.","date":"2024-08-21"},{"id":"7349804715b4d4d75f71568bb3038bffad798b7f","name":"WordPress Multilingual CMS Plugin <= 4.6.12 is vulnerable to Remote Code Execution (RCE)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-wpml-multilingual-cms-plugin-4-6-12-authenticated-contributor-remote-code-execution-via-twig-server-side-template-injection-vulnerability","description":"<p>WordPress Multilingual CMS Plugin <= 4.6.12 is vulnerable to Remote Code Execution (RCE)<\/p><p>Affected Version <= 4.6.12<\/p><p>Fixed in version 4.6.13 <\/p>","date":"2024-08-21"},{"id":"efdcb5a189d47b2ab3177f4ecdad167fe1beddc2","name":"WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-multilingual-cms-4612-authenticatedcontributor-remote-code-execution-via-twig-server-side-template-injection","description":"The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.","date":"2024-08-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."},{"cwe":"CWE-1336","name":"Improper Neutralization of Special Elements Used in a Template Engine","description":"The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"c85ba3412beb2cea71eac56c7bc1ecec260c53d131ff28dfb8f29b989b3388c2","name":"WPML [sitepress-multilingual-cms] >= 3.6.0 - <= 4.7.3","description":null,"operator":{"min_version":"3.6.0","min_operator":"ge","max_version":"4.7.3","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3488","name":"WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3488","description":"The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"16d277844a7de1075149f553706a829cbcd82dda","name":"WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-multilingual-cms-360-473-authenticated-contributor-stored-cross-site-scripting-via-wpml-language-switcher-shortcode","description":"The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-01"},{"id":"c0b2969784d1e83ea905fbe521c937114a6e108d","name":"WordPress Multilingual CMS Plugin 3.6.0-4.7.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-wpml-multilingual-cms-plugin-3-6-0-4-7-3-authenticated-contributor-stored-cross-site-scripting-via-wpml-language-switcher-shortcode","description":"<p>WordPress Multilingual CMS Plugin 3.6.0-4.7.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Multilingual CMS<\/p><p>Fixed in version 4.7.4 <\/p><p>Affected Version 3.6.0-4.7.3<\/p><p>CVE: CVE-2025-3488<\/p>","date":"2025-05-01"},{"id":"EUVD-2025-13295","name":"EUVD-2025-13295","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-13295","description":"The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e16b1721abdfa04905277651c40c304ce961a098a2b3dc0b9c1f50ffd58ace35","name":"WPML [sitepress-multilingual-cms] < 4.9.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12248","name":"CVE-2026-12248","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12248","description":"[en] The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with translator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-08-15"},{"id":"2e2d67d47b2a5d667a823df161e3b701d762ba7d","name":"WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-multilingual-cms-495-authenticated-translator-sql-injection-via-sorting-parameter","description":"The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with translator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-08-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cca791dc716f655d606bd6cdfb8cdc28ccaf0c611a3aedbddd5f9d6a7a518b33","name":"WPML [sitepress-multilingual-cms] < 4.9.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-17509","name":"CVE-2026-17509","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-17509","description":"[en] The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018elementIds\u2019 parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is exploitable due to an authorization bypass where the registered authorization callback fails to execute, allowing any authenticated user regardless of role to access administrative translation functionalities.","date":"2026-09-08"},{"id":"4f48d30853564ad90cdbb38a4471a19b5614fd4c","name":"WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via \u2018elementIds\u2019","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/sitepress-multilingual-cms\/wpml-multilingual-cms-495-incorrect-authorization-to-authenticated-subscriber-sql-injection-via-elementids","description":"The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018elementIds\u2019 parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is exploitable due to an authorization bypass where the registered authorization callback fails to execute, allowing any authenticated user regardless of role to access administrative translation functionalities.","date":"2026-08-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1788840103"}