CVE-2015-2791: Medium severity wpml vulnerability
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2791?
CVE-2015-2791 is considered a critical vulnerability as it allows remote attackers to delete arbitrary content on the website.
How do I fix CVE-2015-2791?
To fix CVE-2015-2791, update the WPML plugin to version 3.1.9 or later.
What kind of exploitation is possible with CVE-2015-2791?
CVE-2015-2791 can be exploited by sending a crafted request to delete posts, pages, and menus on WordPress sites using the WPML plugin.
Which versions of the WPML plugin are affected by CVE-2015-2791?
Versions of the WPML plugin before 3.1.9, up to and including 3.1.8, are affected by CVE-2015-2791.
Who can be targeted by the CVE-2015-2791 vulnerability?
CVE-2015-2791 can target any WordPress site using vulnerable versions of the WPML plugin, making it a significant risk for many sites.