WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter
medium
The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...
- CVSS:
- 6.5
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.6
- Disclosed:
- Aug 14, 2026
CVE-2026-12248 on NVD →
WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode
medium
The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.4
- Affected:
- 3.6.0 – 4.7.3
- Fixed in:
- 4.7.4
- Disclosed:
- May 1, 2025
CVE-2025-3488 on NVD →
WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode
medium
- Affected:
- 3.6.0 – 4.7.4
- Fixed in:
- 4.7.4
- Disclosed:
- May 1, 2025
CVE-2025-3488 on NVD →
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
critical
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access an...
- CVSS:
- 9.9
- Affected:
- up to 4.6.12
- Fixed in:
- 4.6.13
- Disclosed:
- Aug 21, 2024
CVE-2024-6386 on NVD →
WPML Multilingual CMS < 4.6.13 - Contributor+ RCE via Twig Server-Side Template Injection
unknown
- Affected:
- up to 4.6.13
- Fixed in:
- 4.6.13
- Disclosed:
- Aug 21, 2024
CVE-2024-6386 on NVD →
WPML [sitepress-multilingual-cms] < 4.6.13
unknown
[en] The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level...
- Affected:
- up to 4.6.13
- Fixed in:
- 4.6.13
- Disclosed:
- Aug 21, 2024
CVE-2024-6386 on NVD →
WPML [sitepress-multilingual-cms] < 3.1.7.2
unknown
Update plugin.
An unknown person discovered and reported this Full Path Disclosure (FPD) vulnerability in WordPress Multilingual CMS Plugin. This vulnerability has been fixed in version 3.1.7.2.
- Affected:
- up to 3.1.7.2
- Fixed in:
- 3.1.7.2
- Disclosed:
- Oct 18, 2023
WPML <= 4.6.0 - Reflected Cross-Site Scripting via wp_lang
medium
The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...
- CVSS:
- 6.1
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.1
- Disclosed:
- Apr 16, 2023
WPML Multilingual CMS < 4.6.1 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.1
- Disclosed:
- Apr 16, 2023
WPML [sitepress-multilingual-cms] < 4.6.1
unknown
The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.1
- Disclosed:
- Apr 16, 2023
WPML [sitepress-multilingual-cms] < 4.6.1
unknown
The WPML plugin for WordPress is vulnerable to Cross-Site Scripting in versions prior to 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.1
- Disclosed:
- Mar 16, 2023
WPML [sitepress-multilingual-cms] < 4.6.1
unknown
Update the WordPress WPML - WordPress Multilingual plugin to the latest available version (at least 4.6.1).
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WPML - WordPress Multilingual Plugin. This could allow a malicious actor to inject malicious scripts, such as...
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.1
- Disclosed:
- Mar 16, 2023
WPML [sitepress-multilingual-cms] < 4.5.11
unknown
[en] Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.
- Affected:
- up to 4.5.11
- Fixed in:
- 4.5.11
- Disclosed:
- Nov 18, 2022
CVE-2022-38974 on NVD →
WPML [sitepress-multilingual-cms] < 4.5.14
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
- Affected:
- up to 4.5.14
- Fixed in:
- 4.5.14
- Disclosed:
- Nov 17, 2022
CVE-2022-45071 on NVD →
WPML [sitepress-multilingual-cms] < 4.5.14
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
- Affected:
- up to 4.5.14
- Fixed in:
- 4.5.14
- Disclosed:
- Nov 17, 2022
CVE-2022-45072 on NVD →
WPML [sitepress-multilingual-cms] < 4.5.11
unknown
[en] Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).
- Affected:
- up to 4.5.11
- Fixed in:
- 4.5.11
- Disclosed:
- Nov 17, 2022
CVE-2022-38461 on NVD →
WPML <= 4.5.10 - Missing Authorization to Translation Job Status Change
medium
The WPML plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 4.5.10. This is due to improper access controls on authentication for user controls. This makes it possible for subscriber-level attackers to perform status changes of translation jobs.
- CVSS:
- 4.3
- Affected:
- up to 4.5.10
- Fixed in:
- 4.5.11
- Disclosed:
- Nov 9, 2022
CVE-2022-38974 on NVD →
WPML <= 4.5.13 - Cross-Site Request Forgery
medium
The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to change the plugin settings via a forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 4.5.13
- Fixed in:
- 4.5.14
- Disclosed:
- Nov 9, 2022
CVE-2022-45071 on NVD →
WPML <= 4.5.10 - Missing Authorization to Settings Change
medium
The WPML plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 4.5.10. This is due to improper access controls on authorization for user controls. This makes it possible for subscriber-level attackers to perform plugin settings changes. This means allows the change of the...
- CVSS:
- 4.3
- Affected:
- up to 4.5.10
- Fixed in:
- 4.5.11
- Disclosed:
- Nov 9, 2022
CVE-2022-38461 on NVD →
WPML <= 4.5.13 - Cross-Site Request Forgery
medium
The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unspecified function. This makes it possible for unauthenticated attackers to enact the status change of translation jobs via a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 4.5.13
- Fixed in:
- 4.5.14
- Disclosed:
- Nov 9, 2022
CVE-2022-45072 on NVD →
WPML < 4.5.11 - Subscriber+ Translation Job Status Update
unknown
- Affected:
- up to 4.5.11
- Fixed in:
- 4.5.11
- Disclosed:
- Nov 9, 2022
CVE-2022-38974 on NVD →
WPML < 4.5.14 - CSRF
medium
- Affected:
- up to 4.5.14
- Fixed in:
- 4.5.14
- Disclosed:
- Nov 9, 2022
CVE-2022-45072 on NVD →
WPML < 4.5.11 - Subscriber+ Settings Update
unknown
- Affected:
- up to 4.5.11
- Fixed in:
- 4.5.11
- Disclosed:
- Nov 9, 2022
CVE-2022-38461 on NVD →
WPML <= 4.5.10 - Unprotected AJAX Actions
medium
The WPML plugin for WordPress contains several AJAX actions that fail to perform capability checks or nonce checks. These allow authenticated users to set content defaults, update language settings for legacy widgets, and abort translations.
- CVSS:
- 5.4
- Affected:
- up to 4.5.10
- Fixed in:
- 4.5.11
- Disclosed:
- Sep 26, 2022
WPML [sitepress-multilingual-cms] < 4.5.11
unknown
The WPML plugin for WordPress contains several AJAX actions that fail to perform capability checks or nonce checks. These allow authenticated users to set content defaults, update language settings for legacy widgets, and abort translations.
- Affected:
- up to 4.5.11
- Fixed in:
- 4.5.11
- Disclosed:
- Sep 26, 2022
WPML [sitepress-multilingual-cms] < 4.3.8
unknown
[en] The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
- Affected:
- up to 4.3.8
- Fixed in:
- 4.3.8
- Disclosed:
- Mar 14, 2020
CVE-2020-10568 on NVD →
WPML < 4.3.7 - Cross-Site Request Forgery Bypass
high
The sitepress-multilingual-cms (WPML) plugin before 4.3.7 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
- CVSS:
- 8.8
- Affected:
- up to 4.3.7
- Fixed in:
- 4.3.7
- Disclosed:
- Mar 9, 2020
CVE-2020-10568 on NVD →
WPML < 4.3.7 - Authenticated Cross Site Request Forgery leading to Remote Code Execution
critical
- Affected:
- up to 4.3.7
- Fixed in:
- 4.3.7
- Disclosed:
- Mar 9, 2020
CVE-2020-10568 on NVD →
WPML [sitepress-multilingual-cms] >= 2.9.3 - <= 3.2.6
unknown
[en] The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.
- Affected:
- 2.9.3 – 3.2.6
- Fixed in:
- 3.2.6
- Disclosed:
- Sep 25, 2019
CVE-2015-9416 on NVD →
WPML <= 3.6.3 - Unauthenticated Stored Cross-Site Scripting
high
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an unauthenticated theme-localization.php request to wp-admin/admin.php.
- CVSS:
- 7.2
- Affected:
- up to 3.6.3
- Fixed in:
- 4.0
- Disclosed:
- Oct 8, 2018
CVE-2018-18069 on NVD →
WPML [sitepress-multilingual-cms] < 4.0
unknown
[en] process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Oct 8, 2018
CVE-2018-18069 on NVD →
WPML < 4.0 - Unauthenticated Stored Cross-Site Scripting (XSS)
high
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Oct 8, 2018
CVE-2018-18069 on NVD →
WPML [sitepress-multilingual-cms] < 3.1.7.2
unknown
This plugin is prone to a full path disclosure vulnerability.
Update plugin.
- Affected:
- up to 3.1.7.2
- Fixed in:
- 3.1.7.2
- Disclosed:
- Oct 18, 2015
WPML 2.9.3-3.2.6 - Cross-Site Scripting in Accept-Language Header
medium
The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.
- CVSS:
- 6.1
- Affected:
- 2.9.3 – 3.2.6
- Fixed in:
- 3.2.7
- Disclosed:
- Sep 2, 2015
CVE-2015-9416 on NVD →
WPML [sitepress-multilingual-cms] < 3.2.7
unknown
This plugin is prone to a cross site scripting vulnerability in accept-language header.
Update the plugin.
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.7
- Disclosed:
- Sep 2, 2015
WPML 2.9.3-3.2.6 - Cross-Site Scripting (XSS) in Accept-Language Header
medium
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.7
- Disclosed:
- Sep 2, 2015
CVE-2015-9416 on NVD →
WPML [sitepress-multilingual-cms] < 3.1.9.1
unknown
[en] The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.
- Affected:
- up to 3.1.9.1
- Fixed in:
- 3.1.9.1
- Disclosed:
- Mar 30, 2015
CVE-2015-2791 on NVD →
WPML [sitepress-multilingual-cms] < 3.1.9.1
unknown
[en] The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.
- Affected:
- up to 3.1.9.1
- Fixed in:
- 3.1.9.1
- Disclosed:
- Mar 30, 2015
CVE-2015-2792 on NVD →
WPML [sitepress-multilingual-cms] < 3.1.9
unknown
[en] Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9
- Disclosed:
- Mar 17, 2015
CVE-2015-2315 on NVD →
WPML [sitepress-multilingual-cms] < 3.1.9.1
unknown
[en] SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.
- Affected:
- up to 3.1.9.1
- Fixed in:
- 3.1.9.1
- Disclosed:
- Mar 17, 2015
CVE-2015-2314 on NVD →
WPML < 3.1.9 - Multiple Vulnerabilities (Including SQLi)
unknown
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9
- Disclosed:
- Mar 12, 2015
CVE-2015-2314 on NVD →
WPML <= 3.1.9 - SQL Injection via lang Parameter
critical
SQL injection vulnerability in the WPML plugin before 3.1.9.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.
- CVSS:
- 9.8
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9.1
- Disclosed:
- Mar 10, 2015
CVE-2015-2314 on NVD →
WPML <= 3.1.9 - Arbitrary Deletion of Content
high
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.
- CVSS:
- 7.5
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9.1
- Disclosed:
- Mar 10, 2015
CVE-2015-2791 on NVD →
WPML < 3.1.8 - Authorization Bypass
medium
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.
- CVSS:
- 5.4
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9.1
- Disclosed:
- Mar 2, 2015
CVE-2015-2792 on NVD →
WPML [sitepress-multilingual-cms] >= 3.6.0 - <= 4.7.3
unknown
- Affected:
- 3.6.0 – 4.7.3
- Fixed in:
- 4.7.3
CVE-2025-3488 on NVD →
WPML [sitepress-multilingual-cms] < 4.6.1
unknown
The plugin does not escape some URL attributes before outputting them to a page, leading to a Reflected Cross-Site Scripting vulnerability.
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.1