qTranslate X Cleanup and WPML Import

qTranslate X Cleanup and WPML Import has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for qTranslate X Cleanup and WPML Import has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by István Márton. qTranslate X Cleanup and WPML Import is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all qTranslate X Cleanup and WPML Import vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2023-29431

qTranslate X Cleanup and WPML Import <= 3.0.1 - Cross-Site Request Forgery via clean_ajx

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv3.0.3

qTranslate X Cleanup and WPML Import

Amir Helzer

Author

Amir Helzer

3.5(26)
70/100
Last Updated
2026-08-20 (24d ago)
Active Installs
800+
Downloads
108,491
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 7.1
Created
2012-02-29 (15y ago)

qTranslate X plugin was abandoned years ago, and we don’t actively maintain this migration plugin anymore. This plugin can either cleanup the qTranslate X meta-HTML tags from your site and leave just one &#8216;clean’ language, or migrate all languages to WPML’s format. Very important: This plugin will modify the entire content of your database. You must backup your database before attempting to use it. For complete documentation, please refer to the qTranslate uninstall and WPML importer documentation. qTranslate X uninstall and cleanup mode Must-read: All the issues mentioned in the reviews are solved. We are happy to announce the reintroduction of the clean-up mode with plugin version 2.0 This mode is intended if you just want to keep one language in your site and you want to clean up the language meta-tags that qTranslate added. For this mode, you don’t need WPML. Instructions: Save all qTranslate X settings Go to the Plugins admin page and de-activate qTranslate X Install & activate QT Importer Go to Options -> QT Importer, select language to keep and click Start. Migrate all languages from qTranslate X to WPML In this mode, the QT import plugin will convert the language information from qTranslate’s language tags format to WPML’s post-per-language format. For this to work, you must have WPML active in the site (but not necessarily configured). Instructions: Save all qTranslate settings Go to the Plugins admin page and de-activate qTranslate X Have WPML activated, but not yet configured (just activated) Install & activate QT Importer Go to Options -> QT Importer and click Start Add redirects from old URLs to new URLs The import runs in small batches so it doesn’t have timeout issues with large databases. You can run it on sites of any size. During the import process, the plugin generates a set of URL redirect rules. These rules tell visitors and search engines that the URLs in your site have changed (from qTranslate’s format to WPML’s format). When the import completes, you’ll be able to export these rules either as rewrite directives for your .htaccess file or as a PHP file to add to the theme. You can skip the redirect rules, but then, incoming links to internal pages may lead to 404 pages. The import tool converts posts, meta data and taxonomy. We tried to take every possible scenario in mind, but there’s no alternative to manual testing. Please consider spending time reviewing the final result and possible doing some last touch-ups before relaunching the site with WPML.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C