Arbitrary Deletion Vulnerability in WPML Plugin for WordPress
CVE-2015-2791
Currently unrated
What is CVE-2015-2791?
A vulnerability in the WPML plugin prior to version 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus. This is exploited through the 'menu sync' function, where crafted requests can be sent to 'sitepress-multilingual-cms/menu/menus-sync.php', facilitating unauthorized content removal and manipulating website integrity.