CVE-2015-2792: Wpml
High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.
Affected products
- Wpml Wpml: up to and including 3.1.8
Published 2015-03-30. Last modified 2026-06-17.