WPML <= 3.1.9 - Arbitrary Deletion of Content

2015-03-10 00:00
Jouko Pynnöne

Strategic Overview

Status
Patched in 3.1.9.1
Affected PluginWPML Multilingual CMS
Affected Version<= 3.1.9
CVSS7.5High
CVECVE-2015-2791
View all WPML Multilingual CMS vulnerabilities

Vulnerability Overview

The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.

Technical Analysis

REMEDIATION: Update to version 3.1.9.1, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C