Collected research
The Full Story of CVE-2024-6386: Remote Code Execution in WPML
Explains how a contributor-level user could reach WPML's Twig shortcode rendering and obtain server-side template injection. Quote-free string construction bypasses the surrounding syntax constraints and turns the injection into remote code execution.
Record
- Researcher
- Jonas Lejon and @wpscans
- Published by
- WPSec
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jonas Lejon and @wpscans, first published at the original source. Preserved copies are kept so the citation survives its host.