CVE-2015-2314

WPML < 3.1.8 - SQL Injection via HTTP Referer Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-2314.

AI-analyzed exploit summary The document details three vulnerabilities in WPML (WordPress Multilingual Plugin), including an unauthenticated SQL injection via crafted HTTP referer, arbitrary post/page deletion due to missing access controls, and a reflected XSS vulnerability. It provides technical explanations and proof-of-concept examples for each issue.

Description

SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/36414

The document details three vulnerabilities in WPML (WordPress Multilingual Plugin), including an unauthenticated SQL injection via crafted HTTP referer, arbitrary post/page deletion due to missing access controls, and a reflected XSS vulnerability. It provides technical explanations and proof-of-concept examples for each issue.

Classification
Writeup 100%
Attack Type
Sqli | Xss | Other
Complexity
Trivial
Reliability
Reliable
Target: WPML (WordPress Multilingual Plugin) < 3.1.9.1
No auth needed
Prerequisites: Access to the target WordPress site · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit x_refsource_misc
http://klikki.fi/adv/wpml.html
Vendor Advisory x_refsource_confirm
http://wpml.org/2015/03/wpml-security-update-bug-and-fix/
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/119541
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Mar/71
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534862/100/0/threaded

Scores

EPSS 0.0712
EPSS Percentile 93.4%

Details

CWE
CWE-89
Status published
Products (1)
wpml/wpml < 3.1.8
Published Mar 17, 2015
Tracked Since Feb 18, 2026