Static Code Injection Vulnerability in XCloner Plugin for WordPress
CVE-2015-4338

Currently unrated

Key Information:

Vendor

Wordpress

Status
Vendor
CVE Published:
17 June 2015

What is CVE-2015-4338?

The XCloner plugin version 3.1.2 for WordPress is prone to a static code injection vulnerability. This flaw enables remote authenticated users to inject arbitrary PHP code into language files through the Translation LM_FRONT_* fields. It poses a significant risk as an attacker could manipulate language files, potentially resulting in arbitrary command execution. Affected users should update to the latest version of the plugin to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.