CVEs Blog | G5 Cyber Security

CVE-2015-2314 – SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress

SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2314

Reference (s):

Exit mobile version