WPML is a WordPress multilingual content management plugin that sits deep in the WordPress ecosystem, enabling translation and language handling across web properties of varying complexity. Its vulnerability profile centers on a single plugin product and recurs through web-application input-handling and access-control weakness classes—including cross-site scripting, cross-site request forgery, code injection, and improper access control—that are characteristic of WordPress plugins operating on user-supplied content. The vendor's disclosures frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpml over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6386HIGH The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing in | Aug 21, 2024 | 8.8 | 43 | NO | NO |
CVE-2018-18069MEDIUM process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authen | Oct 8, 2018 | 6.1 | 38 | NO | YES |
CVE-2015-2791MEDIUM The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multil | Mar 30, 2015 | 6.4 | 31 | NO | YES |
CVE-2015-2314HIGH SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer heade | Mar 17, 2015 | 7.5 | 31 | NO | YES |
CVE-2015-2315MEDIUM Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a | Mar 17, 2015 | 4.3 | 23 | NO | YES |
CVE-2022-45071HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress. | Nov 17, 2022 | 8.8 | 21 | NO | NO |
CVE-2015-2792HIGH The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary action | Mar 30, 2015 | 7.5 | 20 | NO | NO |
CVE-2025-3488MEDIUM The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in versions 3.6.0 - 4.7.3 due to insufficient input san | May 2, 2025 | 5.4 | 18 | NO | NO |
CVE-2022-38974MEDIUM Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the tra | Nov 18, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-45072MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress. | Nov 17, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpml.
Media articles that mention a CVE ID that affects a product developed by Wpml — matched by CVE ID, not by vendor name.