WPScan检测到WPML旧版本漏洞,3.9.4版本仍告警如何解决?
Hey there, I’ve dealt with similar false positive scanner alerts before, so let’s break down how to get this sorted:
1. Update WPScan’s Vulnerability Database First
WPScan relies on a community-maintained vulnerability database to map issues to plugin versions. Sometimes the database doesn’t properly reflect that newer releases (like your 3.9.4) include all older fixes.
Run this command to pull the latest vulnerability data:
wpscan --update
After updating, re-scan your site—this often clears up false alerts immediately.
2. Manually Confirm the Vulnerabilities Are Fixed
To be fully confident your site is secure, cross-check WPML’s official changelog (available on their official platform) to verify:
- The Full Path Disclosure issue was patched in 3.1.7.2, and this fix is included in 3.9.4
- The SQL injection and related vulnerabilities were resolved in 3.1.9, a version far older than your current installation
- The Accept-Language Header XSS was fixed in 3.2.7, and this protection is part of all subsequent WPML releases including 3.9.4
You can also do a quick code check:
- For path disclosure: Look for files that might output full server paths on errors and confirm they’re sanitized in your 3.9.4 files
- For XSS: Verify the
Accept-Languageheader input is filtered before any output - For SQLi: Check that database queries in previously vulnerable areas use prepared statements or proper sanitization
3. Ignore Specific Vulnerabilities in WPScan (Temporary Fix)
If updating the database doesn’t resolve the alerts, you can tell WPScan to skip these specific vulnerability IDs during scans:
To ignore all three in a single scan:
wpscan --url your-site-url --ignore-vulnerability-id 6104 --ignore-vulnerability-id 7843 --ignore-vulnerability-id 8173
For permanent ignoring, add these IDs to WPScan’s configuration file (refer to WPScan’s docs for the config file location on your system).
4. Report the False Positive to WPScan
If you’ve confirmed these are definitely false positives, reach out to the WPScan team to update their database. This helps other users avoid the same confusion—you can submit feedback via their official GitHub repo or support portal.
内容的提问来源于stack exchange,提问作者Toni Michel Caubet

