SQL Injection Vulnerability in Smartcat Translator for WPML Plugin
CVE-2025-9451
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2025
What is CVE-2025-9451?
The Smartcat Translator for WPML plugin for WordPress is susceptible to time-based SQL injection attacks via the 'orderby' parameter. This vulnerability arises from inadequate escaping of user-supplied input and insufficient preparation in the SQL query. As a result, authenticated attackers with Author-level access or higher can manipulate the SQL queries to inject additional commands, potentially leading to the exposure of sensitive database information.
Affected Version(s)
Smartcat Translator for WPML * <= 3.1.69