WordPress WPML Multilingual CMS plugin Remote Code Execution (RCE)

ISGroup Cybersecurity

The WPML Multilingual CMS plugin for WordPress, used by over 1 million sites, is vulnerable to a critical authenticated Remote Code Execution (RCE) flaw exploitable by users with Contributor privileges or higher via server-side template injection (SSTI) in the Twig engine. This vulnerability affects all versions up to 4.6.12.

Productsitepress-multilingual-cms
Date2024-08-28 15:32:41

Technical Summary

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 4.6.12, via server-side template injection (SSTI) in the Twig engine. This is due to a lack of input validation and sanitization in the render function. This allows authenticated attackers, with at least Contributor privileges, to execute code on the server.

Recommendations

Update to the latest available version.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert