CVE-2024-6386

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpml:wpml:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-08-21 21:15

Updated : 2024-09-27 13:25


NVD link : CVE-2024-6386

Mitre link : CVE-2024-6386

CVE.ORG link : CVE-2024-6386


JSON object : View

Products Affected

wpml

  • wpml
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

CWE-94

Improper Control of Generation of Code ('Code Injection')