WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode
WPML
Minimum safe version
4.6.13
Update to 4.6.13 or later to address 19 fixable vulnerabilities
CVE-2024-6386
WPML Multilingual CMS < 4.6.1 - Reflected Cross-Site Scripting
WordPress Multilingual CMS Plugin <= 3.1.7.1 is vulnerable to Full Path Disclosure (FPD)
WPML <= 4.6.1 - Cross-Site Scripting
WPML <= 4.6.0 - Reflected Cross-Site Scripting via wp_lang
WordPress WPML - WordPress Multilingual Plugin < 4.6.1 is vulnerable to Cross Site Scripting (XSS)
WPML <= 4.5.10 - Unprotected AJAX Actions
CVE-2022-45072
CVE-2022-38974
CVE-2022-38461
CVE-2022-45071
WordPress WPML Plugin <= 3.2.6 - Cross Site Scripting
WordPress Multilingual CMS Plugin <= 3.1.7.1 - Full Path Disclosure
CVE-2015-2315
CVE-2015-2314
CVE-2015-2792
CVE-2015-2791
CVE-2018-18069
CVE-2015-9416
CVE-2020-10568