Prisna Google Website Translator Plugin Vulnerable to PHP Object Injection
CVE-2024-8514
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 25 September 2024
What is CVE-2024-8514?
The Google Website Translator plugin for WordPress presents a PHP Object Injection vulnerability due to unsafe deserialization of the 'prisna_import' parameter. This flaw affects all versions up to 1.4.11 and allows authenticated users with Administrator-level access to inject malicious PHP objects. While no existing payload chains are known in the vulnerable environment itself, the presence of additional plugins or themes may expose the site to enhanced risks, such as unauthorized file deletions, sensitive data retrieval, or remote code execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Prisna GWT β Google Website Translator * <= 1.4.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved