WordPress Translation Plugin Vulnerability Affects +1 Million Sites

0
WordPress Translation Plugin Vulnerability Affects +1 Million Sites

A critical vulnerability was discovered in the WPML WordPress plugin, affecting over a million installations. The vulnerability allows an authenticated attacker to perform remote code execution, potentially leading to a total site takeover. It is listed as rated 9.9 out of 10 by the Common Vulnerabilities and Exposures (CVE) organization.

WPML Plugin Vulnerability

The plugin vulnerability is due to a lack of a security check called sanitization, a process for filtering user input data to protect against the upload of malicious files. Lack of sanitization in this input makes the plugin vulnerable to a Remote Code Execution.

The vulnerability exists within a function of a shortcode for creating a custom language switcher. The function renders the content from the shortcode into a plugin template but without sanitizing the data, making it vulnerable to code injection.

The vulnerability affects all versions of the WPML WordPress plugin up to and including 4.6.12.

Timeline Of Vulnerability

Wordfence discovered the vulnerability in late June and promptly notified the publishers of WPML which remained unresponsive for about a month and a half, confirming response on August 1, 2024.

Users of the paid version of Wordfence received protection eight days after discovery of the vulnerability, the free users of Wordfence received protection on July 27th.

Users of the WPML plugin who did not use either version of Wordfence did not receive protection from WPML until August 20th, when the publishers finally issued a patch in version 4.6.13.

Plugin Users Urged To Update

Wordfence urges all users of the WPML plugin to make sure they are using the latest version of the plugin, WPML 4.6.13.

They wrote:

“We urge users to update their sites with the latest patched version of WPML, version 4.6.13 at the time of this writing, as soon as possible.”

Read more about the vulnerability at Wordfence:

1,000,000 WordPress Sites Protected Against Unique Remote Code Execution Vulnerability in WPML WordPress Plugin

Featured Image by Shutterstock/Luis Molinero

FOLLOW US ON GOOGLE NEWS

 

Read original article here

Denial of responsibility! Search Engine Codex is an automatic aggregator of the all world’s media. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials, please contact us by email – [email protected]. The content will be deleted within 24 hours.

Leave A Reply

Your email address will not be published.

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More