What the vulnerability does
01Description
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Explanation of Vulnerability in Simple Terms
02Summary
WPML versions up to 4.6.12 contain a privilege escalation vulnerability allowing authenticated users with low privileges to gain full control over the site, including reading sensitive data, modifying content, and disrupting service. The vulnerability affects the scope beyond the plugin itself. A patch is available in a version newer than 4.6.12.
What an attacker can do
03Attacker Capabilities
Read all site data, modify any content, disable the site, or create admin accounts.
Potential impact on your site
04Site Impact
Any low-privilege user can take over your site and access all data, content, and user information.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
August 21, 2024
CVE published
April 8, 2026
Record updated