CVE-2015-2791 | WPML Plugin up to 3.1.8 menus-sync.php sync access control (Bug 130810 / EDB-36414)
A vulnerability has been found in WPML Plugin up to 3.1.8 and classified as critical. This vulnerability affects the function sync of the file sitepress-multilingual-cms/menu/menus-sync.php. The manipulation leads to improper access controls.
This vulnerability was named CVE-2015-2791. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.