Input validation vulnerability in WPML String Translation 3.2.5

The WPML String Translation plugin for WordPress is vulnerable to an attack known as SQL Injection in versions up to and including 3.2.5. SQL Injection is when an attacker, with administrator-level permissions or higher, can add extra information to existing queries which can allow them to gain access to sensitive information in the database. This is possible because the plugin does not properly escape user supplied parameters and does not properly prepare existing SQL queries.

Detected in:

WPML String Translation Importer fixed vulnerable versions: >= 0 <= 0
wpml-string-translation fixed vulnerable versions: >= * <= 3.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.