CVE-2015-2314: Wpml

High severity, CVSS 7.5. EPSS: 7.1% chance of exploitation in the next 30 days.

SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

Affected products

  • Wpml Wpml: up to and including 3.1.8

Published 2015-03-17. Last modified 2026-06-17.