CVE Database /
CVE-2018-18069
CVE · Medium
CVE-2018-18069 — WPML [sitepress-multilingual-cms] < 4.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-18069
|
WPML [sitepress-multilingual-cms] < 4.0 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 4.0
|
4.0 |
2018-10-08 |
—
|
CVE-2018-18069
The WPML plugin version 3.6.3 and earlier contains a cross-site scripting vulnerability in the process_forms function that can be exploited through the theme-localization.php file. An attacker can inject malicious code via locale_file_name parameters (such as locale_file_name_en) sent to wp-admin/admin.php without requiring authentication. This vulnerability allows unauthorized users to execute arbitrary scripts in the context of affected WordPress installations.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings