CVE-2015-2314: SQL Injection
Published Mar 17, 2015
·Updated
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.
Affected Software
1 affected component
WPML Wpml Wordpress<=3.1.8
Event History
Mar 17, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2314?
CVE-2015-2314 is considered a high severity SQL injection vulnerability in the WPML plugin for WordPress.
2
How do I fix CVE-2015-2314?
To fix CVE-2015-2314, update the WPML plugin to the latest version 3.1.9 or higher.
3
What type of attack can exploit CVE-2015-2314?
CVE-2015-2314 can be exploited by remote attackers to execute arbitrary SQL commands on the affected WordPress site.
4
Which versions of the WPML plugin are affected by CVE-2015-2314?
CVE-2015-2314 affects WPML plugin versions prior to 3.1.9.
5
How does CVE-2015-2314 work?
CVE-2015-2314 allows SQL injection through the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.