8.8
CVSSv3

CVE-2020-10568

Published: 14/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The sitepress-multilingual-cms (WPML) plugin prior to 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

onthegosystems sitepress-multilingual-cms 4.3.7

onthegosystems sitepress-multilingual-cms