plugin

Sitepress Multilingual Cms Vulnerabilities

46 known security issues reported for the Sitepress Multilingual Cms WordPress plugin. Most recent disclosed Aug 14, 2026.

3 critical 4 high 14 medium

Running Sitepress Multilingual Cms on your site? Check whether your installed version is affected.

Scan your site free

WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter

medium

The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...

CVSS:
6.5
Affected:
up to 4.9.5
Fixed in:
4.9.6
Disclosed:
Aug 14, 2026

CVE-2026-12248 on NVD →

WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode

medium

The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.4
Affected:
3.6.0 – 4.7.3
Fixed in:
4.7.4
Disclosed:
May 1, 2025

CVE-2025-3488 on NVD →

WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode

medium
Affected:
3.6.0 – 4.7.4
Fixed in:
4.7.4
Disclosed:
May 1, 2025

CVE-2025-3488 on NVD →

WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection

critical

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access an...

CVSS:
9.9
Affected:
up to 4.6.12
Fixed in:
4.6.13
Disclosed:
Aug 21, 2024

CVE-2024-6386 on NVD →

WPML Multilingual CMS < 4.6.13 - Contributor+ RCE via Twig Server-Side Template Injection

unknown
Affected:
up to 4.6.13
Fixed in:
4.6.13
Disclosed:
Aug 21, 2024

CVE-2024-6386 on NVD →

WPML [sitepress-multilingual-cms] < 4.6.13

unknown

[en] The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level...

Affected:
up to 4.6.13
Fixed in:
4.6.13
Disclosed:
Aug 21, 2024

CVE-2024-6386 on NVD →

WPML [sitepress-multilingual-cms] < 3.1.7.2

unknown

Update plugin. An unknown person discovered and reported this Full Path Disclosure (FPD) vulnerability in WordPress Multilingual CMS Plugin. This vulnerability has been fixed in version 3.1.7.2.

Affected:
up to 3.1.7.2
Fixed in:
3.1.7.2
Disclosed:
Oct 18, 2023

WPML <= 4.6.0 - Reflected Cross-Site Scripting via wp_lang

medium

The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...

CVSS:
6.1
Affected:
up to 4.6.0
Fixed in:
4.6.1
Disclosed:
Apr 16, 2023

WPML Multilingual CMS < 4.6.1 - Reflected Cross-Site Scripting

medium
Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Apr 16, 2023

WPML [sitepress-multilingual-cms] < 4.6.1

unknown

The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Apr 16, 2023

WPML [sitepress-multilingual-cms] < 4.6.1

unknown

The WPML plugin for WordPress is vulnerable to Cross-Site Scripting in versions prior to 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Mar 16, 2023

WPML [sitepress-multilingual-cms] < 4.6.1

unknown

Update the WordPress WPML - WordPress Multilingual plugin to the latest available version (at least 4.6.1). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WPML - WordPress Multilingual Plugin. This could allow a malicious actor to inject malicious scripts, such as...

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Mar 16, 2023

WPML [sitepress-multilingual-cms] < 4.5.11

unknown

[en] Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.

Affected:
up to 4.5.11
Fixed in:
4.5.11
Disclosed:
Nov 18, 2022

CVE-2022-38974 on NVD →

WPML [sitepress-multilingual-cms] < 4.5.14

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

Affected:
up to 4.5.14
Fixed in:
4.5.14
Disclosed:
Nov 17, 2022

CVE-2022-45071 on NVD →

WPML [sitepress-multilingual-cms] < 4.5.14

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

Affected:
up to 4.5.14
Fixed in:
4.5.14
Disclosed:
Nov 17, 2022

CVE-2022-45072 on NVD →

WPML [sitepress-multilingual-cms] < 4.5.11

unknown

[en] Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

Affected:
up to 4.5.11
Fixed in:
4.5.11
Disclosed:
Nov 17, 2022

CVE-2022-38461 on NVD →

WPML <= 4.5.10 - Missing Authorization to Translation Job Status Change

medium

The WPML plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 4.5.10. This is due to improper access controls on authentication for user controls. This makes it possible for subscriber-level attackers to perform status changes of translation jobs.

CVSS:
4.3
Affected:
up to 4.5.10
Fixed in:
4.5.11
Disclosed:
Nov 9, 2022

CVE-2022-38974 on NVD →

WPML <= 4.5.13 - Cross-Site Request Forgery

medium

The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to change the plugin settings via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 4.5.13
Fixed in:
4.5.14
Disclosed:
Nov 9, 2022

CVE-2022-45071 on NVD →

WPML <= 4.5.10 - Missing Authorization to Settings Change

medium

The WPML plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 4.5.10. This is due to improper access controls on authorization for user controls. This makes it possible for subscriber-level attackers to perform plugin settings changes. This means allows the change of the...

CVSS:
4.3
Affected:
up to 4.5.10
Fixed in:
4.5.11
Disclosed:
Nov 9, 2022

CVE-2022-38461 on NVD →

WPML <= 4.5.13 - Cross-Site Request Forgery

medium

The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unspecified function. This makes it possible for unauthenticated attackers to enact the status change of translation jobs via a forged request gr...

CVSS:
4.3
Affected:
up to 4.5.13
Fixed in:
4.5.14
Disclosed:
Nov 9, 2022

CVE-2022-45072 on NVD →

WPML < 4.5.11 - Subscriber+ Translation Job Status Update

unknown
Affected:
up to 4.5.11
Fixed in:
4.5.11
Disclosed:
Nov 9, 2022

CVE-2022-38974 on NVD →

WPML < 4.5.11 - Subscriber+ Settings Update

unknown
Affected:
up to 4.5.11
Fixed in:
4.5.11
Disclosed:
Nov 9, 2022

CVE-2022-38461 on NVD →

WPML <= 4.5.10 - Unprotected AJAX Actions

medium

The WPML plugin for WordPress contains several AJAX actions that fail to perform capability checks or nonce checks. These allow authenticated users to set content defaults, update language settings for legacy widgets, and abort translations.

CVSS:
5.4
Affected:
up to 4.5.10
Fixed in:
4.5.11
Disclosed:
Sep 26, 2022

WPML [sitepress-multilingual-cms] < 4.5.11

unknown

The WPML plugin for WordPress contains several AJAX actions that fail to perform capability checks or nonce checks. These allow authenticated users to set content defaults, update language settings for legacy widgets, and abort translations.

Affected:
up to 4.5.11
Fixed in:
4.5.11
Disclosed:
Sep 26, 2022

WPML [sitepress-multilingual-cms] < 4.3.8

unknown

[en] The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

Affected:
up to 4.3.8
Fixed in:
4.3.8
Disclosed:
Mar 14, 2020

CVE-2020-10568 on NVD →

WPML < 4.3.7 - Cross-Site Request Forgery Bypass

high

The sitepress-multilingual-cms (WPML) plugin before 4.3.7 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

CVSS:
8.8
Affected:
up to 4.3.7
Fixed in:
4.3.7
Disclosed:
Mar 9, 2020

CVE-2020-10568 on NVD →

WPML < 4.3.7 - Authenticated Cross Site Request Forgery leading to Remote Code Execution

critical
Affected:
up to 4.3.7
Fixed in:
4.3.7
Disclosed:
Mar 9, 2020

CVE-2020-10568 on NVD →

WPML [sitepress-multilingual-cms] >= 2.9.3 - <= 3.2.6

unknown

[en] The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.

Affected:
2.9.3 – 3.2.6
Fixed in:
3.2.6
Disclosed:
Sep 25, 2019

CVE-2015-9416 on NVD →

WPML <= 3.6.3 - Unauthenticated Stored Cross-Site Scripting

high

process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an unauthenticated theme-localization.php request to wp-admin/admin.php.

CVSS:
7.2
Affected:
up to 3.6.3
Fixed in:
4.0
Disclosed:
Oct 8, 2018

CVE-2018-18069 on NVD →

WPML [sitepress-multilingual-cms] < 4.0

unknown

[en] process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Oct 8, 2018

CVE-2018-18069 on NVD →

WPML < 4.0 - Unauthenticated Stored Cross-Site Scripting (XSS)

high
Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Oct 8, 2018

CVE-2018-18069 on NVD →

WPML [sitepress-multilingual-cms] < 3.1.7.2

unknown

This plugin is prone to a full path disclosure vulnerability. Update plugin.

Affected:
up to 3.1.7.2
Fixed in:
3.1.7.2
Disclosed:
Oct 18, 2015

WPML 2.9.3-3.2.6 - Cross-Site Scripting in Accept-Language Header

medium

The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.

CVSS:
6.1
Affected:
2.9.3 – 3.2.6
Fixed in:
3.2.7
Disclosed:
Sep 2, 2015

CVE-2015-9416 on NVD →

WPML [sitepress-multilingual-cms] < 3.2.7

unknown

This plugin is prone to a cross site scripting vulnerability in accept-language header. Update the plugin.

Affected:
up to 3.2.7
Fixed in:
3.2.7
Disclosed:
Sep 2, 2015

WPML 2.9.3-3.2.6 - Cross-Site Scripting (XSS) in Accept-Language Header

medium
Affected:
up to 3.2.7
Fixed in:
3.2.7
Disclosed:
Sep 2, 2015

CVE-2015-9416 on NVD →

WPML [sitepress-multilingual-cms] < 3.1.9.1

unknown

[en] The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.

Affected:
up to 3.1.9.1
Fixed in:
3.1.9.1
Disclosed:
Mar 30, 2015

CVE-2015-2791 on NVD →

WPML [sitepress-multilingual-cms] < 3.1.9.1

unknown

[en] The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.

Affected:
up to 3.1.9.1
Fixed in:
3.1.9.1
Disclosed:
Mar 30, 2015

CVE-2015-2792 on NVD →

WPML [sitepress-multilingual-cms] < 3.1.9

unknown

[en] Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.

Affected:
up to 3.1.9
Fixed in:
3.1.9
Disclosed:
Mar 17, 2015

CVE-2015-2315 on NVD →

WPML [sitepress-multilingual-cms] < 3.1.9.1

unknown

[en] SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

Affected:
up to 3.1.9.1
Fixed in:
3.1.9.1
Disclosed:
Mar 17, 2015

CVE-2015-2314 on NVD →

WPML < 3.1.9 - Multiple Vulnerabilities (Including SQLi)

unknown
Affected:
up to 3.1.9
Fixed in:
3.1.9
Disclosed:
Mar 12, 2015

CVE-2015-2314 on NVD →

WPML <= 3.1.9 - SQL Injection via lang Parameter

critical

SQL injection vulnerability in the WPML plugin before 3.1.9.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

CVSS:
9.8
Affected:
up to 3.1.9
Fixed in:
3.1.9.1
Disclosed:
Mar 10, 2015

CVE-2015-2314 on NVD →

WPML <= 3.1.9 - Arbitrary Deletion of Content

high

The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.

CVSS:
7.5
Affected:
up to 3.1.9
Fixed in:
3.1.9.1
Disclosed:
Mar 10, 2015

CVE-2015-2791 on NVD →

WPML < 3.1.8 - Authorization Bypass

medium

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.

CVSS:
5.4
Affected:
up to 3.1.9
Fixed in:
3.1.9.1
Disclosed:
Mar 2, 2015

CVE-2015-2792 on NVD →

WPML [sitepress-multilingual-cms] >= 3.6.0 - <= 4.7.3

unknown
Affected:
3.6.0 – 4.7.3
Fixed in:
4.7.3

CVE-2025-3488 on NVD →

WPML [sitepress-multilingual-cms] < 4.6.1

unknown

The plugin does not escape some URL attributes before outputting them to a page, leading to a Reflected Cross-Site Scripting vulnerability.

Affected:
up to 4.6.1
Fixed in:
4.6.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database