7.5
CVSSv2

CVE-2015-2314

Published: 17/03/2015 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the WPML plugin prior to 3.1.9 for WordPress allows remote malicious users to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

Vulnerable Product Search on Vulmon Subscribe to Product

wpml wpml

Exploits

OVERVIEW ========== WPML is the industry standard for creating multi-lingual WordPress sites Three vulnerabilities were found in the plug-in The most serious of them, an SQL injection problem, allows anyone to read the contents of the WordPress database, including user details and password hashes, without authentication System administrators s ...