PT-2024-39066 · WordPress · Prisna Gwt – Google Website Translator

Lesor101

·

Published

2024-09-24

·

Updated

2024-10-02

·

CVE-2024-8514

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Prisna GWT – Google Website Translator plugin for WordPress versions up to, and including, 1.4.11
Description: The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection via deserialization of untrusted input from the prisna import parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations: Update the Prisna GWT – Google Website Translator plugin for WordPress to a version later than 1.4.11 to fix the PHP Object Injection vulnerability. As a temporary workaround, consider restricting access to the prisna import parameter to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-8514

Affected Products

Prisna Gwt – Google Website Translator