Web Hack List

Collected research

The Full Story of CVE-2024-6386: Remote Code Execution in WPML

Explains how a contributor-level user could reach WPML's Twig shortcode rendering and obtain server-side template injection. Quote-free string construction bypasses the surrounding syntax constraints and turns the injection into remote code execution.

Record

Researcher
Jonas Lejon and @wpscans
Published by
WPSec
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jonas Lejon and @wpscans, first published at the original source. Preserved copies are kept so the citation survives its host.