Prisna Google Website Translator Plugin Vulnerable to PHP Object Injection
CVE-2024-8514
7.2HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 25 September 2024
What is CVE-2024-8514?
The Google Website Translator plugin for WordPress presents a PHP Object Injection vulnerability due to unsafe deserialization of the 'prisna_import' parameter. This flaw affects all versions up to 1.4.11 and allows authenticated users with Administrator-level access to inject malicious PHP objects. While no existing payload chains are known in the vulnerable environment itself, the presence of additional plugins or themes may expose the site to enhanced risks, such as unauthorized file deletions, sensitive data retrieval, or remote code execution.
Affected Version(s)
Prisna GWT – Google Website Translator * <= 1.4.11