CVE

Id
79591  
CVE No.
CVE-2015-2314  
Status
Candidate  
Description
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.  
Phase
Assigned (20150317)  
Votes
None (candidate not yet proposed)  
Comments