CVE-2020-10568: Onthegosystems Sitepress-Multilingual-CMS

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

Affected products

  • Onthegosystems Sitepress-Multilingual-CMS: before 4.3.7 (fixed in 4.3.7); version 4.3.7 only

Published 2020-03-14. Last modified 2026-06-17.