WordPress Plugin Vulnerabilities

ImageMagick Engine < 1.7.11 - Administrator+ OS Command Injection

Description

The ImageMagick Engine plugin for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.

Proof of Concept

Affects Plugins

Fixed in 1.7.11

References

Classification

Type
COMMAND INJECTION
OWASP top 10
CWE

Miscellaneous

Original Researcher
Chaiwat Thongyaem
Submitter
Chaiwat Thongyaem
Submitter website
Verified
Yes

Timeline

Publicly Published
2024-06-26 (about 1 year ago)
Added
2024-09-20 (about 1 year ago)
Last Updated
2024-10-01 (about 1 year ago)

Other