Skip to content Skip to sidebar

This thread is resolved. Here is a description of the problem and solution.

Problem:
The client reported a critical security alert from Wordfence concerning a file in the wpml-string-translation.3.5.0 update, identified as potentially malicious or unsafe. The file in question is located at wp-content/plugins/wpml-string-translation/lib/StringScanning/vendor/wp-cli/wp-cli/features/context.feature, and it is flagged as a backdoor with suspicious modifications.
Solution:
We have identified this issue as a false-positive warning by Wordfence. This will be addressed and resolved in the upcoming WPML release. For more details, please visit our errata page at https://wpml.org/errata/wordfence-reports-a-false-positive-security-warning-with-wpml-4-9-0/.

If this solution does not seem relevant to your case, or if it appears outdated, we highly recommend checking related known issues at https://wpml.org/known-issues/, verifying the version of the permanent fix, and confirming that you have installed the latest versions of themes and plugins. Should you need further assistance, please do not hesitate to open a new support ticket at WPML support forum.

100% of people find this useful.

This is the technical support forum for WPML - the multilingual WordPress plugin.

Everyone can read, but only WPML clients can post here. WPML team is replying on the forum 6 days per week, 22 hours per day.

Tagged: 

This topic contains 1 reply, has 0 voices.

Last updated by Jean-Paul 2 months, 1 week ago.

Assisted by: Noman.

Author Posts
February 9, 2026 at 4:55 pm #17806422

Jean-Paul

The security plugin Wordfence is alerting me to a critical issue with a file in the wpml-string-translation.3.5.0 update.

File appears to be malicious or unsafe: wp-content/plugins/wpml-string-translation/lib/StringScanning/vendor/wp-cli/wp-cli/features/context.feature

File Type: Not a core, theme, or plugin file from wordpress.org.

Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: file_put_contents( __DIR__ . '/wp-admin/admin.php'

The issue type is: Backdoor:PHP/wpAuditEX.11980
Description: Suspicious modification of files in WP core

February 9, 2026 at 5:15 pm #17806518

Noman

Hi,

Thank you for contacting WPML support. This is a false-positive warning from Wordfence, and it will be fixed in the next WPML release.

You can find the details on our errata page here:
https://wpml.org/errata/wordfence-reports-a-false-positive-security-warning-with-wpml-4-9-0/

Thank you

February 9, 2026 at 6:32 pm #17806697

Jean-Paul

Thanks for the quick response.