S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-18069 Scanner

CVE-2018-18069 scanner - Cross-Site Scripting (XSS) vulnerability in WPML plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-18069
6.1
CVSS

process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The WPML (sitepress-multilingual-cms) plugin is a popular tool used for WordPress sites to translate website content into multiple languages. It is designed to allow web administrators to manage translations of posts, pages, taxonomy, and menus, as well as other aspects of a website. With a user-friendly interface and a variety of features, the WPML plugin provides an efficient way for website owners to offer content to diverse audiences. Through the WPML plugin, administrators can serve multiple languages by providing a drop down menu to choose the preferred language for website visitors. 

Recently, a vulnerability known as CVE-2018-18069 has been detected in the plugin. This vulnerability is present in the plugin's process_forms function and can lead to a cross-site scripting (XSS) attack. The vulnerability is triggered through the use of any "locale_file_name_" parameter in an authenticated theme-localization.php request to wp-admin/admin.php. The issue, when exploited, can allow an attacker to execute arbitrary scripts or take unauthorized actions on behalf of the website owner, such as stealing user information or manipulating website content.

When exploited by a malicious actor, CVE-2018-18069 can have serious consequences for users and website owners. Attackers can gain access to sensitive information and manipulate website content, leading to reputation damage, financial loss, and other damages. For larger organizations, a successful attack can lead to significant regulatory or legal penalties.

In conclusion, it is essential for website owners to be aware of vulnerabilities in their digital assets and to take proactive steps to protect against them. With the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets, as well as receive customized alerts and recommendations to protect against them. By staying informed and implementing effective security measures, website owners can help ensure the safety and integrity of their online presence.

 

REFERENCES

Solution Advice

Fortunately, there are actions that website owners and administrators can take to protect themselves against this vulnerability. These include:

  • Update the WPML plugin to the latest version to ensure that the issue has been patched and addressed.
  • Limit the use of the authenticated theme-localization.php to only trusted users and connections.
  • Monitor website traffic and access logs for suspicious activity, including unauthorized access attempts or unusual file requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.