Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wpml MEDIUM 5.4
CVE-2025-3488

The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.…

Fix: 4.7.4+
Fix from $1,600 2025-05-02
Wpml HIGH 8.8
CVE-2024-6386EPSS 26%

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injec…

Fix: 4.6.13+
Fix from $1,950 2024-08-21
Wpml HIGH 8.8
CVE-2022-45071

Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

Fix: 4.5.14+
Fix from $1,950 2022-11-17
Wpml MEDIUM 6.1
CVE-2018-18069EPSS 13%

process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as lo…

Fix: after 3.6.3
Fix from $1,600 2018-10-08
Wpml HIGH 7.5
CVE-2015-2792

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce chec…

Fix: after 3.1.8
Fix from $1,950 2015-03-30
Wpml MEDIUM 6.4
CVE-2015-2791EPSS 13%

The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a craf…

Fix: after 3.1.8
Fix from $1,600 2015-03-30
Wpml HIGH 7.5
CVE-2015-2314EPSS 7%

SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang para…

Fix: after 3.1.8
Fix from $1,950 2015-03-17