CVE

CVE-2015-2791 — WPML [sitepress-multilingual-cms] < 3.1.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-2314, CVE-2015-2791, CVE-2015-2792 WPML [sitepress-multilingual-cms] < 3.1.9.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 3.1.9.1 3.1.9.1 2015-03-10

CVE-2015-2314, CVE-2015-2791, CVE-2015-2792

The WPML plugin before version 3.1.9.1 contains a SQL injection vulnerability where attackers can run arbitrary SQL queries by manipulating the "lang" parameter found in the HTTP Referer header when making requests to the wp-link-ajax action affecting comments and feed functionality. Users should upgrade to version 3.1.9.1 or later to remediate this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.