What is CVE-2026-12248?
This is an SQL Injection vulnerability in the WPML Multilingual CMS plugin for WordPress via the 'sorting' parameter. All versions up to and including 4.9.5 are affected, allowing an authenticated user to interfere with database queries. Updating to the latest plugin version is recommended.
Azərbaycanca: Bu, WordPress üçün WPML Multilingual CMS pluginində 'sorting' parametri vasitəsilə SQL Injection zəifliyidir. 4.9.5 versiyasına qədər bütün versiyalar təsirlənir və autentifikasiya olunmuş istifadəçiyə verilənlər bazasına müdaxilə etməyə imkan yaradır. Pluginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WPML Multilingual CMS plugin are affected by CVE-2026-12248?
This vulnerability affects all versions of the WPML Multilingual CMS plugin up to and including 4.9.5.
What is the recommended action to protect against CVE-2026-12248?
Updating the WPML Multilingual CMS plugin to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.