CVE Database /
CVE-2024-6386
CVE · High
CVE-2024-6386 — WPML [sitepress-multilingual-cms] < 4.6.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6386
|
WPML [sitepress-multilingual-cms] < 4.6.13 |
Improper Control of Generation of Code ('Code Injection') |
High
8.8
|
< 4.6.13
|
4.6.13 |
2024-08-21 |
—
|
CVE-2024-6386
A security flaw exists in WPML plugin versions prior to 4.6.12 that allows malicious users with contributor or higher permissions to inject arbitrary code into Twig templates via unvalidated input passed to the render function, potentially leading to remote code execution on affected servers. This vulnerability arises from inadequate validation and sanitization of user-submitted data.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings