WPML Multilingual CMS

WPML Multilingual CMS has 16 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 16 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 9.9 out of 10. Severity breakdown: 2 critical and 3 high. 2022 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 4 of the records (25%). Other recurring categories include Cross-Site Request Forgery (CSRF), SQL Injection.

Every one of the 16 issues recorded for WPML Multilingual CMS has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, most of them (4) reported by Dave Jong.

01234567891002.03.2015Today02.03.20155.4WPML < 3.1.8 - Authorization Bypass CVSS 5.4 · 02.03.201510.03.20159.8WPML <= 3.1.9 - SQL Injection via lang Parameter CVSS 9.8 · 10.03.20157.5WPML <= 3.1.9 - Arbitrary Deletion of Content CVSS 7.5 · 10.03.201502.09.20156.1WPML 2.9.3-3.2.6 - Cross-Site Scripting in Accept-Language Header CVSS 6.1 · 02.09.201508.10.20187.2WPML <= 3.6.3 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 08.10.201809.03.20208.8WPML < 4.3.7 - Cross-Site Request Forgery Bypass CVSS 8.8 · 09.03.202026.09.20225.4WPML <= 4.5.10 - Unprotected AJAX Actions CVSS 5.4 · 26.09.202209.11.20224.3WPML <= 4.5.10 - Missing Authorization to Translation Job Status Change CVSS 4.3 · 09.11.20224.3WPML <= 4.5.13 - Cross-Site Request Forgery CVSS 4.3 · 09.11.20224.3WPML <= 4.5.13 - Cross-Site Request Forgery CVSS 4.3 · 09.11.20224.3WPML <= 4.5.10 - Missing Authorization to Settings Change CVSS 4.3 · 09.11.202216.04.20236.1WPML <= 4.6.0 - Reflected Cross-Site Scripting via wp_lang CVSS 6.1 · 16.04.202321.08.20249.9WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection CVSS 9.9 · 21.08.202401.05.20256.4WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode CVSS 6.4 · 01.05.202514.08.20266.5WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter CVSS 6.5 · 14.08.202607.09.20266.5WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’ CVSS 6.5 · 07.09.2026

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

16

Get automatic notifications for all WPML Multilingual CMS vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.9CVE-2024-6386

WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection

Read the full analysis

Vulnerability Records

16 records
2026-09-07 00:00CVE-2026-17509
6.5
Medium
h0xiloYes
2026-08-14 00:00CVE-2026-12248
6.5
Medium
Yuto HyakumotoYes
2025-05-01 17:11CVE-2025-3488
6.4
Medium
stealthcopterYes
2024-08-21 08:00CVE-2024-6386
9.9
Critical
stealthcopterYes
2023-04-16 00:00N/A
6.1
Medium
Deepak kumarYes
2022-11-09 00:00CVE-2022-38974
4.3
Medium
Dave JongYes
2022-11-09 00:00CVE-2022-45071
4.3
Medium
Dave JongYes
2022-11-09 00:00CVE-2022-45072
4.3
Medium
Dave JongYes
2022-11-09 00:00CVE-2022-38461
4.3
Medium
Dave JongYes
2022-09-26 00:00N/A
5.4
Medium
AnonymousYes
Showing 1–10 of 16 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C