Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: 1 Million WordPress Sites Affected by WPML Plugin Vulnerability
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: 1 Million WordPress Sites Affected by WPML Plugin Vulnerability
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Vulnerabilities » 1 Million WordPress Sites Affected by WPML Plugin Vulnerability

Vulnerabilities

1 Million WordPress Sites Affected by WPML Plugin Vulnerability

WordPress admins need to update their WPML plugin immediately due to a serious security vulnerability.

Marco Rizal
Last updated: August 28, 2024 7:01 am
By Marco Rizal - Editor, Journalist 3 Min Read
Share
1 Million WordPress Sites Affected by WPML Plugin Vulnerability
SHARE

WPML, a popular WordPress plugin with over a million active installations, recently faced a serious security issue.

Security experts have found a serious vulnerability that could allow authorized users to inject malicious code into websites.

This vulnerability, referred to as a Remote Code Execution (RCE) flaw, enabled attackers to potentially gain control of affected websites. Fortunately, a new update for the WPML plugin has been released to fix this issue.

The vulnerability was identified by researchers at Wordfence, a leading security company that specializes in WordPress security.

Based on their findings, it appears that there is an issue with the PHP template engine called Twig, which is utilized by WPML.

Users who have been authenticated and have access to the post editor have the ability to exploit this vulnerability by injecting malicious code templates on the server side.

It is possible for someone with limited access to a WordPress site, like a contributor, to run harmful scripts that could put the entire site and its visitors at risk.

The vulnerability was initially reported on June 19, 2024, by a security researcher named  via the Wordfence Bug Bounty Program.

The researcher received a generous reward of $1,639.00 for this discovery. Wordfence promptly verified the report and immediately started notifying the WPML development team.

Initially, there were some challenges in establishing communication with the plugin's developers.

Although there were some initial communication challenges, Wordfence and WPML managed to work together effectively.

The WPML team recently released version 4.6.13 of the plugin, which includes important security updates.

WordPress admins should update to the latest version immediately, as all versions of WPML up to and including 4.6.12 are affected.

The severity of this vulnerability is highlighted by its CVSS score of 9.9 out of 10, which is considered critical.

Therefore Wordfence strongly recommends that all WPML users update their plugins to the latest version, 4.6.13 or newer, to protect against this vulnerability.

Administrators should check their sites to ensure they are not running an outdated version of the plugin.

Not updating could put websites at risk of being attacked, potentially leading to complete site compromise.

More Stories

Google Patches Serious Android Security Flaws in September Update

Critical Flaw Found in Two-Factor Authenticator YubiKey Will Likely Not Be Patched

This SSL Flaw Puts Millions of .mobi Domains at Risk of Being Hijacked

Newly Discovered Vulnerability Poses Risk to Millions of Online Stores

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

Mantra Faces Crisis After OM Token Crashes 90% in a Day

April 14, 2025

Solana (SOL) on the Verge of a Breakout: Could $300 Be the Next Target?

April 14, 2025

You might also like

Major Security Flaws Found in Widely Used Discourse Forum

Major Security Flaws Found in Widely-Used Discourse Forum

Critical Wordpress Vulnerabilities

Critical WordPress Vulnerabilities and Malicious Plugin Infections

How a YouTube vulnerability can be used to steal files

How a YouTube Vulnerability Can Be Used to Steal Files

ATM Machine Hacked to Show Hill Climb Racing Instead of Transactions

ATM Machine Hacked to Show Hill Climb Racing Instead of Transactions

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?