Arbitrary Deletion Vulnerability in WPML Plugin for WordPress
CVE-2015-2791

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
30 March 2015

Summary

A vulnerability in the WPML plugin prior to version 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus. This is exploited through the 'menu sync' function, where crafted requests can be sent to 'sitepress-multilingual-cms/menu/menus-sync.php', facilitating unauthorized content removal and manipulating website integrity.

References

EPSS Score

13% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.