Impact
The WPML Multilingual CMS plugin for WordPress has a time‑based SQL injection flaw in the elementIds parameter in all versions up to 4.9.5. Insufficient escaping and lack of prepared statements allow an attacker to append malicious SQL to existing queries, enabling extraction of sensitive database contents. The vulnerability is coupled with an authorization bypass that lets any authenticated user with Subscriber level or higher access administrative translation functions.
Affected Systems
WPML Multilingual CMS by WPML, versions up to and including 4.9.5.
Risk and Exploitability
The issue carries a CVSS score of 6.5, indicating medium severity. Although no EPSS score is available and it is not listed in the CISA KEV catalog, the requirement for only an authenticated Subscriber account lowers the entry barrier for exploitation. With the bypassed authorization checks, an attacker can execute the injection to read database data, which threatens confidentiality of site contents, user information, and metadata. The risk is significant for installations that allow wide Subscriber access to translation features and that have not been patched to a later version.
OpenCVE Enrichment