CVE-2015-2791: Wpml
Medium severity, CVSS 6.4. EPSS: 13.3% chance of exploitation in the next 30 days.
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.
Affected products
- Wpml Wpml: up to and including 3.1.8
Published 2015-03-30. Last modified 2026-06-17.