WordPress users who had the WPML plugin installed before version 3.1.9.1 were vulnerable to a security issue called ‘SQL injection’. This issue allowed people outside of the website to send malicious commands through the ‘lang parameter’ in the website’s HTTP Referer header. If successful