HomeSecurityRCE Vulnerability on 1,000,000 WordPress Sites Allows Backend Control

RCE vulnerability in 1,000,000 WordPress sites allows backend control

A critical remote code execution (RCE) vulnerability (CVE-2024-6386) affects over 1,000,000 active installations of the WordPress Multilingual Plugin (WPML).

See also: 390,000 WordPress accounts stolen by hackers

WordPress RCE vulnerability

This flaw, stemming from a Server-Side Template Injection (SSTI) in the Twig template engine, allowed attackers to execute arbitrary code on affected websites.

The WordPress RCE vulnerability, rated critical with a CVSS score of 9.9, posed a serious risk to both website owners and users before it was addressed.

WPML is a premium plugin widely used for creating multilingual websites, allowing users to seamlessly switch between languages ​​on the same site. The vulnerability affected all WPML versions up to 4.6.12, leaving millions of WordPress sites vulnerable to attacks.

See also: Hunk Companion: Critical vulnerability in WordPress plugin

Security researcher stealthcopter, armed with extensive experience in application security, reported the issue. Despite the size of this discovery, it took 62 days to patch the vulnerability, and the researcher received a modest reward of $1,639.

RCE vulnerability in 1,000,000 WordPress sites allows backend control

SSTI vulnerabilities occur when user input is not properly encapsulated in templates using a rendering engine like Twig. By injecting malicious payloads in the form of valid template syntax, attackers can gain control of a server, read sensitive data, or escalate their attack to achieve remote code execution.

In the case of WordPress WPML, the RCE vulnerability was located in the plugin's shortcode blocks; attackers could test for SSTI vulnerabilities by sending simple payloads, such as mathematical expressions, to check if they were evaluated.

If the output showed 28, as stealthcopter observed, it indicated that the input was being executed on the server, a clear indication of SSTI.

See also: WPForms bug allows refunds on millions of WordPress sites

Remote Code Execution (RCE) refers to a security vulnerability that allows a threat actor to execute malicious code on a remote system or device. This vulnerability can be exploited through security holes in software or applications, allowing an attacker to gain unauthorized access, execute commands, and cause serious damage. Addressing such vulnerabilities requires regular software updates, strong security practices, and the use of advanced threat detection tools.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS