Input validation vulnerability in qTranslate X Cleanup and WPML Import 3.0.1

The qTranslate X Cleanup and WPML Import plugin for WordPress has a security issue in versions up to and including 3.0.1, which makes it possible for unauthenticated attackers to trigger the ‘clean’ functionality without permission. This is because the plugin does not have the proper security measures in place to prevent people from sending a forged request. For example, an attacker could trick a site administrator into clicking on a link.

Detected in:

qTranslate X Cleanup and WPML Import fixed vulnerable versions: >= * <= 3.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.