Static Code Injection Vulnerability in XCloner Plugin for WordPress
CVE-2015-4338
Currently unrated
Summary
The XCloner plugin version 3.1.2 for WordPress is prone to a static code injection vulnerability. This flaw enables remote authenticated users to inject arbitrary PHP code into language files through the Translation LM_FRONT_* fields. It poses a significant risk as an attacker could manipulate language files, potentially resulting in arbitrary command execution. Affected users should update to the latest version of the plugin to mitigate the risks associated with this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved