CVE-2024-6386 is a critical Remote Code Execution (RCE) vulnerability affecting all versions of the WPML plugin for WordPress up to and including 4.6.12. This flaw stems from insufficient input validation and sanitization in the render function, specifically due to a Twig Server-Side Template Injection. Authenticated attackers with Contributor-level access or higher can exploit this to execute arbitrary code on the server. The vulnerability carries a high CVSS score of 8.8, indicating a severe impact with high confidentiality, integrity, and availability compromise. It is easily exploitable over the network with low attack complexity and no user interaction required. The FAUCET Risk Score is exceptionally high at 99/100, and its EPSS score is in the top 1% of all CVEs. While there is no evidence of active exploitation in the wild (not in KEV), and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community attention with multiple discussions and media coverage from reputable cybersecurity outlets, suggesting a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.6.13CPE matchmatch criteria | cpe:2.3:a:wpml:wpml:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 4.6.12CPE match | cpe:2.3:a:wpml:wpml:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.