
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-17509 is a time-based SQL Injection vulnerability in the WPML Multilingual CMS plugin for WordPress, affecting all versions up to and including 4.9.5. The flaw exists in the elementIds parameter and is compounded by an authorization bypass that allows any authenticated user — including those with Subscriber-level access — to reach administrative translation functionalities. It was published on September 8, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). Insufficient escaping of the user-supplied elementIds parameter, combined with inadequate SQL query preparation, allows attackers to append arbitrary SQL statements to existing queries. A critical aggravating factor is an authorization bypass: the registered authorization callback fails to execute, meaning any authenticated WordPress user — regardless of assigned role — can invoke administrative translation endpoints that should be restricted. This enables time-based blind SQL injection over the network with low attack complexity and no user interaction required (GitHub Advisory).
Successful exploitation allows any authenticated attacker to extract sensitive information from the WordPress database, including user credentials, personal data, configuration secrets, and other stored content. The confidentiality impact is rated High, while integrity and availability are unaffected. Because even low-privileged subscriber accounts can exploit this flaw, the effective attack surface on multi-user WordPress sites is broad, and extracted credentials could facilitate further account takeover or lateral movement (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.237% (15th percentile), indicating a currently low probability of exploitation within 30 days. The CVE status is listed as "Deferred" and it is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD SSVC assessment notes exploitation as "none" and the attack as non-automatable.
elementIds parameter — normally restricted to administrators.elementIds value containing a time-based blind SQL injection payload (e.g., using SLEEP() or BENCHMARK() functions) to infer database contents character by character based on server response delays.elementIds parameter; requests exhibiting consistent time delays (indicative of SLEEP()-based payloads).SLEEP, BENCHMARK, UNION, SELECT) in query parameters.Update the WPML Multilingual CMS plugin to a version newer than 4.9.5, which addresses both the SQL injection and the authorization bypass (GitHub Advisory, WPML Changelog). As interim mitigations, restrict subscriber-level user registrations on WordPress installations where not required, and deploy Web Application Firewall (WAF) rules to detect and block SQL injection attempts targeting the elementIds parameter. Monitor the Wordfence threat intelligence entry for updated guidance.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."