Static Code Injection Vulnerability in XCloner Plugin for WordPress
CVE-2015-4338

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
17 June 2015

Summary

The XCloner plugin version 3.1.2 for WordPress is prone to a static code injection vulnerability. This flaw enables remote authenticated users to inject arbitrary PHP code into language files through the Translation LM_FRONT_* fields. It poses a significant risk as an attacker could manipulate language files, potentially resulting in arbitrary command execution. Affected users should update to the latest version of the plugin to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.