Critical WPML Plugin Flaw Exposes WordPress Sites to Remote Code Execution
The WPML WordPress multilingual plugin contains a serious security vulnerability that, in some cases, might provide authorized users the ability to remotely execute arbitrary code.
This issue affects all versions of the plugin prior to 4.6.13, which was released on August 20, 2024. It is tagged as CVE-2024-6386 (CVSS score: 9.9).
The problem allows authorized attackers with Contributor-level access and above to execute code on the server since input validation and sanitization are absent.
A well-liked plugin for creating multilingual WordPress websites is called WPML. More than a million installations are currently in use.
The issue, according to security researcher stealthcopter, is with how the plugin handles shortcodes, which are used to add post content including audio rea...

