CVE-2024-6386

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpml:wpml:*:*:*:*:*:wordpress:*:*

History

08 Apr 2026, 19:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.9
Summary (en) The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. (en) The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

27 Sep 2024, 13:25

Type Values Removed Values Added
First Time Wpml wpml
Wpml
CVSS v2 : unknown
v3 : 9.9
v2 : unknown
v3 : 8.8
CWE CWE-94
References () https://sec.stealthcopter.com/wpml-rce-via-twig-ssti/ - () https://sec.stealthcopter.com/wpml-rce-via-twig-ssti/ - Exploit, Third Party Advisory
References () https://wpml.org/ - () https://wpml.org/ - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/f7fc91cc-e529-4362-8269-bf7ee0766e1e?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/f7fc91cc-e529-4362-8269-bf7ee0766e1e?source=cve - Third Party Advisory
CPE cpe:2.3:a:wpml:wpml:*:*:*:*:*:wordpress:*:*

22 Aug 2024, 12:48

Type Values Removed Values Added
Summary
  • (es) El complemento WPML para WordPress es vulnerable a la ejecución remota de código en todas las versiones hasta la 4.6.12 incluida a través de la inyección de plantilla del lado del servidor Twig. Esto se debe a que falta validación de entrada y desinfección en la función de renderizado. Esto hace posible que atacantes autenticados, con acceso de nivel de colaborador y superior, ejecuten código en el servidor.

21 Aug 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-21 21:15

Updated : 2026-04-08 19:22


NVD link : CVE-2024-6386

Mitre link : CVE-2024-6386

CVE.ORG link : CVE-2024-6386


JSON object : View

Products Affected

wpml

  • wpml
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

CWE-94

Improper Control of Generation of Code ('Code Injection')