WPML records
11 published records for vendor wpml.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-284 Improper Access Control1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2024-6386Proof of concept | WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injectionwpml · wpml · CWE-1336 | High8.8 | — | 25.5% | Aug 21, 2024 |
35Monitor | CVE-2022-45071No exploit | WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerabilitywpml · wpml · CWE-352 | High8.8 | — | 0.3% | Nov 17, 2022 |
32Monitor | CVE-2015-2314Proof of concept | SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the wpml · wpml · CWE-89 | High7.5 | — | 7.1% | Mar 17, 2015 |
31Monitor | CVE-2015-2792No exploit | The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nwpml · wpml · CWE-284 | High7.5 | — | 3.8% | Mar 30, 2015 |
29Monitor | CVE-2015-2791Proof of concept | The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus vwpml · wpml · CWE-264 | Medium6.4 | — | 13.3% | Mar 30, 2015 |
28Monitor | CVE-2018-18069Proof of concept | process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (swpml · wpml · CWE-79 | Medium6.1 | — | 13.2% | Oct 8, 2018 |
21Monitor | CVE-2025-3488No exploit | WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcodewpml · wpml · CWE-79 | Medium5.4 | — | 0.3% | May 2, 2025 |
19Monitor | CVE-2015-2315Proof of concept | Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web scripwpml · wpml · CWE-79 | Medium4.3 | — | 7.0% | Mar 17, 2015 |
17Monitor | CVE-2022-38974No exploit | WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerabilitywpml · wpml · CWE-264 | Medium4.3 | — | 0.5% | Nov 18, 2022 |
17Monitor | CVE-2022-38461No exploit | WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerabilitywpml · wpml · CWE-264 | Medium4.3 | — | 0.5% | Nov 17, 2022 |
17Monitor | CVE-2022-45072No exploit | WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerabilitywpml · wpml · CWE-352 | Medium4.3 | — | 0.3% | Nov 17, 2022 |
- CVE-2024-638643Plan
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
HighCVSS 8.8Proof of conceptEPSS 26%wpml · wpmlAug 21, 2024
- CVE-2022-4507135Monitor
WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%wpml · wpmlNov 17, 2022
- CVE-2015-231432Monitor
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 7%wpml · wpmlMar 17, 2015
- CVE-2015-279231Monitor
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass n
HighCVSS 7.5No exploitEPSS 4%wpml · wpmlMar 30, 2015
- CVE-2015-279129Monitor
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus v
MediumCVSS 6.4Proof of conceptEPSS 13%wpml · wpmlMar 30, 2015
- CVE-2018-1806928Monitor
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (s
MediumCVSS 6.1Proof of conceptEPSS 13%wpml · wpmlOct 8, 2018
- CVE-2025-348821Monitor
WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode
MediumCVSS 5.4No exploitEPSS 0%wpml · wpmlMay 2, 2025
- CVE-2015-231519Monitor
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web scrip
MediumCVSS 4.3Proof of conceptEPSS 7%wpml · wpmlMar 17, 2015
- CVE-2022-3897417Monitor
WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 1%wpml · wpmlNov 18, 2022
- CVE-2022-3846117Monitor
WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 1%wpml · wpmlNov 17, 2022
- CVE-2022-4507217Monitor
WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%wpml · wpmlNov 17, 2022