Input validation vulnerability in WPML 3.1.9

WordPress users who had the WPML plugin installed before version 3.1.9.1 were vulnerable to a security issue called ‘SQL injection’. This issue allowed people outside of the website to send malicious commands through the ‘lang parameter’ in the website’s HTTP Referer header. If successful

Detected in:

WPML fixed vulnerable versions: >= * <= 3.1.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.