Prisna Google Website Translator Plugin Vulnerable to PHP Object Injection
CVE-2024-8514

7.2HIGH

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
25 September 2024

What is CVE-2024-8514?

The Google Website Translator plugin for WordPress presents a PHP Object Injection vulnerability due to unsafe deserialization of the 'prisna_import' parameter. This flaw affects all versions up to 1.4.11 and allows authenticated users with Administrator-level access to inject malicious PHP objects. While no existing payload chains are known in the vulnerable environment itself, the presence of additional plugins or themes may expose the site to enhanced risks, such as unauthorized file deletions, sensitive data retrieval, or remote code execution.

Affected Version(s)

Prisna GWT – Google Website Translator * <= 1.4.11

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lesor101
.