First published: Tue Mar 17 2015(Updated: )
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WPML | <=3.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2314 is considered a high severity SQL injection vulnerability in the WPML plugin for WordPress.
To fix CVE-2015-2314, update the WPML plugin to the latest version 3.1.9 or higher.
CVE-2015-2314 can be exploited by remote attackers to execute arbitrary SQL commands on the affected WordPress site.
CVE-2015-2314 affects WPML plugin versions prior to 3.1.9.
CVE-2015-2314 allows SQL injection through the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.