A critical remote code execution (RCE) vulnerability (CVE-2024-6386) affects over 1,000,000 active installations of the WordPress Multilingual Plugin (WPML).
See also: 390,000 WordPress accounts stolen by hackers

This flaw, stemming from a Server-Side Template Injection (SSTI) in the Twig template engine, allowed attackers to execute arbitrary code on affected websites.
The WordPress RCE vulnerability, rated critical with a CVSS score of 9.9, posed a serious risk to both website owners and users before it was addressed.
WPML is a premium plugin widely used for creating multilingual websites, allowing users to seamlessly switch between languages on the same site. The vulnerability affected all WPML versions up to 4.6.12, leaving millions of WordPress sites vulnerable to attacks.
See also: Hunk Companion: Critical vulnerability in WordPress plugin
Security researcher stealthcopter, armed with extensive experience in application security, reported the issue. Despite the size of this discovery, it took 62 days to patch the vulnerability, and the researcher received a modest reward of $1,639.

SSTI vulnerabilities occur when user input is not properly encapsulated in templates using a rendering engine like Twig. By injecting malicious payloads in the form of valid template syntax, attackers can gain control of a server, read sensitive data, or escalate their attack to achieve remote code execution.
In the case of WordPress WPML, the RCE vulnerability was located in the plugin's shortcode blocks; attackers could test for SSTI vulnerabilities by sending simple payloads, such as mathematical expressions, to check if they were evaluated.
If the output showed 28, as stealthcopter observed, it indicated that the input was being executed on the server, a clear indication of SSTI.
See also: WPForms bug allows refunds on millions of WordPress sites
Remote Code Execution (RCE) refers to a security vulnerability that allows a threat actor to execute malicious code on a remote system or device. This vulnerability can be exploited through security holes in software or applications, allowing an attacker to gain unauthorized access, execute commands, and cause serious damage. Addressing such vulnerabilities requires regular software updates, strong security practices, and the use of advanced threat detection tools.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
