Extension WordPress
Vulnérabilités WPML Multilingual CMS
Cette page rassemble les failles publiées pour WPML Multilingual CMS, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPML Multilingual CMS
14 fiches
WPML Multilingual CMS 3.6.0 – 4.7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode
The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 – 4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
3.6.0-4.7.3
4.7.4
01/05/2025
WPML Multilingual CMS <= 4.6.12 – Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This…
*-4.6.12
4.6.13
21/08/2024
WPML <= 4.6.0 – Reflected Cross-Site Scripting via wp_lang
The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.6.0
4.6.1
16/04/2023
WPML <= 4.5.10 – Missing Authorization to Settings Change
The WPML plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 4.5.10. This is due to improper access controls on authorization for user controls. This makes it possible for subscriber-level attackers to…
*-4.5.10
4.5.11
09/11/2022
WPML <= 4.5.13 – Cross-Site Request Forgery
The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unspecified function. This makes it possible for unauthenticated attackers…
*-4.5.13
4.5.14
09/11/2022
WPML <= 4.5.13 – Cross-Site Request Forgery
The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers…
*-4.5.13
4.5.14
09/11/2022
WPML <= 4.5.10 – Missing Authorization to Translation Job Status Change
The WPML plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 4.5.10. This is due to improper access controls on authentication for user controls. This makes it possible for subscriber-level attackers to perform…
*-4.5.10
4.5.11
09/11/2022
WPML <= 4.5.10 – Unprotected AJAX Actions
The WPML plugin for WordPress contains several AJAX actions that fail to perform capability checks or nonce checks. These allow authenticated users to set content defaults, update language settings for legacy widgets, and abort translations.
*-4.5.10
4.5.11
26/09/2022
WPML < 4.3.7 – Cross-Site Request Forgery Bypass
The sitepress-multilingual-cms (WPML) plugin before 4.3.7 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
[*, 4.3.7)
4.3.7
09/03/2020
WPML <= 3.6.3 – Unauthenticated Stored Cross-Site Scripting
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an unauthenticated theme-localization.php request to wp-admin/admin.php.
*-3.6.3
4.0
08/10/2018
WPML 2.9.3-3.2.6 – Cross-Site Scripting in Accept-Language Header
The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.
2.9.3-3.2.6
3.2.7
02/09/2015
WPML <= 3.1.9 – Arbitrary Deletion of Content
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.
*-3.1.9
3.1.9.1
10/03/2015
WPML <= 3.1.9 – SQL Injection via lang Parameter
SQL injection vulnerability in the WPML plugin before 3.1.9.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.
*-3.1.9
3.1.9.1
10/03/2015
WPML < 3.1.8 – Authorization Bypass
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action…
[*, 3.1.9)
3.1.9.1
02/03/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.