Authorization Bypass in WPML Plugin for WordPress
CVE-2015-2792

Currently unrated

Key Information:

Vendor

Wordpress

Status
Vendor
CVE Published:
30 March 2015

What is CVE-2015-2792?

The WPML plugin for WordPress, prior to version 3.1.9, contains a vulnerability that inadequately manages multiple actions in a single request. This flaw can be exploited by remote attackers to bypass nonce validation checks, potentially allowing unauthorized actions to be executed through crafted POST and GET requests. The risk arises when a valid nonce is combined with specific action parameters, leading to potential misuse of the plugin's functionalities.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2015-2792 : Authorization Bypass in WPML Plugin for WordPress