← Back to browse · API

CVE-2024-6386

Severity
CRITICAL
CVSS
9.9
EPSS
0.25533
Risk score
48.54
CISA KEV
No
PoC
No
Published
2024-08-21
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-47493, GHSA-Q8GR-QPFG-HV8P
Products
WPML:WPML 0 ≤4.6.12
Sources
euvd EUVD-2024-47493

Description

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

References