PT-2024-5841 · WordPress · Wpml
Matthew Rollings
+1
·
Published
2024-02-09
·
Updated
2025-01-07
·
CVE-2024-6386
9.9
Critical
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WPML versions up to, and including, 4.6.12
Description:
The WPML plugin for WordPress is vulnerable to Remote Code Execution via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function, making it possible for authenticated attackers with Contributor-level access and above to execute code on the server. Over a million WordPress sites are at risk. The vulnerability is related to the lack of input validation, allowing attackers to execute code remotely.
Recommendations:
Update to version 4.6.13 or later to patch the critical flaw.
As a temporary workaround, consider disabling the render function or restricting access to the vulnerable plugin until a patch is applied.
Exploit
Fix
RCE
Code Injection
Related Identifiers
Affected Products
References · 66
- 🔥 https://github.com/argendo/CVE-2024-6386⭐ 4 · Exploit
- 🔥 https://sec.stealthcopter.com/wpml-rce-via-twig-ssti · Exploit
- https://bdu.fstec.ru/vul/2024-06586 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2024-6386 · Security Note
- https://twitter.com/zoomeye_team/status/1828270743165022487 · Twitter Post
- https://wpml.org · Note
- https://twitter.com/cyberwarzo44531/status/1828705836610261278 · Twitter Post
- https://twitter.com/Dinosn/status/1828274147752833163 · Twitter Post
- https://twitter.com/XynikIT/status/1828455805957394576 · Twitter Post
- https://wordfence.com/threat-intel/vulnerabilities/id/f7fc91cc-e529-4362-8269-bf7ee0766e1e?source=cve · Note
- https://twitter.com/Akitra_Inc/status/1876690365048308024 · Twitter Post
- https://twitter.com/securestep9/status/1829876459336569279 · Twitter Post
- https://twitter.com/jvquantum/status/1828649143314637068 · Twitter Post
- https://twitter.com/H4ckManac/status/1828724245586698403 · Twitter Post
- https://t.me/cvedetector/3845 · Telegram Post