Arbitrary Deletion Vulnerability in WPML Plugin for WordPress
CVE-2015-2791
Currently unrated
Summary
A vulnerability in the WPML plugin prior to version 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus. This is exploited through the 'menu sync' function, where crafted requests can be sent to 'sitepress-multilingual-cms/menu/menus-sync.php', facilitating unauthorized content removal and manipulating website integrity.
References
EPSS Score
13% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved