Skip Navigation

This is the technical support forum for WPML - the multilingual WordPress plugin.

Everyone can read, but only WPML clients can post here. WPML team is replying on the forum 6 days per week, 22 hours per day.

Tagged: 

This topic contains 3 replies, has 2 voices.

Last updated by Mihai Apetrei 1 year, 10 months ago.

Assisted by: Mihai Apetrei.

Author Posts
July 28, 2023 at 4:47 pm #14119109

marcoP-30

I am trying to: update WPML String Translation as we have a vulnerability problem

Link to a page where the issue can be seen: hidden link

I expected to see:I cannot update as there is not an update available yet. Please inform what actions we need to take.

July 28, 2023 at 4:58 pm #14119167

Mihai Apetrei
WPML Supporter since 03/2018

Languages: English (English )

Timezone: Europe/Bucharest (GMT+03:00)

Hi there.

You would need to update the "WPML String Translation" add-on to the very latest version: 3.2.6

If you can't see it, please go to Plugins > Add new > Commercial > and click "check for updates" > then check the box for WPML String Translation > and click the update button.

I recommend that you first create a full website backup.

Please let me know how things go.

Mihai Apetrei

July 28, 2023 at 5:58 pm #14119539

marcoP-30

Hi Mihai,

Thanks for your prompt support. We have gone trough your recommendations and updated it to 3.2.6 as in the image, but this version is the one that presents a vulnerability in fact. See the alert from WPengine.

Please advice what measures can we take.

Thank you so much

Screenshot 2023-07-28 at 19.55.19.png
Screenshot 2023-07-28 at 19.56.14.png
July 31, 2023 at 7:14 pm #14129279

Mihai Apetrei
WPML Supporter since 03/2018

Languages: English (English )

Timezone: Europe/Bucharest (GMT+03:00)

Hi there.

There are databases online with vulnerabilities that have not been updated yet (patchstack for example which were already notified by us).

You should not see the prompt in the following days (in case you still see it).

But I can assure you that the issue was in the older version and with this new one, it is fixed.

Mihai