WordPress Translation Plugin Vulnerability Affects +1 Million Sites


A critical vulnerability was discovered in the WPML WordPress plugin, affecting over a million installations. The vulnerability allows an authenticated attacker to perform remote code execution, potentially leading to a total site takeover. It is listed as rated 9.9 out of 10 by the Common Vulnerabilities and Exposures (CVE) organization.

WPML Plugin Vulnerability

The plugin vulnerability is due to a lack of a security check called sanitization, a process for filtering user input data to protect against the upload of malicious files. Lack of sanitization in this input makes the plugin vulnerable to a Remote Code Execution.

The vulnerability exists within a function of a shortcode for creating a custom language switcher. The function renders the content from the shortcode into a plugin template but without sanitizing the data, making it vulnerable to code injection.

The vulnerability affects all versions of the WPML WordPress plugin up to and including 4.6.12.

Timeline Of Vulnerability

Wordfence discovered the vulnerability in late June and promptly notified the publishers of WPML which remained unresponsive for about a month and a half, confirming response on August 1, 2024.

Users of the paid version of Wordfence received protection eight days after discovery of the vulnerability, the free users of Wordfence received protection on July 27th.

Users of the WPML plugin who did not use either version of Wordfence did not receive protection from WPML until August 20th, when the publishers finally issued a patch in version 4.6.13.

Plugin Users Urged To Update

Wordfence urges all users of the WPML plugin to make sure they are using the latest version of the plugin, WPML 4.6.13.

They wrote:

“We urge users to update their sites with the latest patched version of WPML, version 4.6.13 at the time of this writing, as soon as possible.”

Read more about the vulnerability at Wordfence:

1,000,000 WordPress Sites Protected Against Unique Remote Code Execution Vulnerability in WPML WordPress Plugin

Featured Image by Shutterstock/Luis Molinero



Source link

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

We Know You Better!
Subscribe To Our Newsletter
Be the first to get latest updates and
exclusive content straight to your email inbox.
Yes, I want to receive updates
No Thanks!
close-link

Subscribe to our newsletter

Sign-up to get the latest marketing tips straight to your inbox.
SUBSCRIBE!
Give it a try, you can unsubscribe anytime.