<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-vulnerability-patched-in-wpml-wordpress-plugin-immediate-update-required-6odzwg5zv" -->

---
title: Critical Vulnerability Patched in WPML WordPress Plugin:...
description: A critical Remote Code Execution (RCE) vulnerability in the WPML WordPress plugin has been patched. With a CVSS score of 9.9, the issue affects all versions...
canonical: https://daily.dev/posts/critical-vulnerability-patched-in-wpml-wordpress-plugin-immediate-update-required-6odzwg5zv
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical Vulnerability Patched in WPML WordPress Plugin: Immediate Update Required | daily.dev
og:description: A critical Remote Code Execution (RCE) vulnerability in the WPML WordPress plugin has been patched. With a CVSS score of 9.9, the issue affects all versions...
og:url: https://daily.dev/posts/critical-vulnerability-patched-in-wpml-wordpress-plugin-immediate-update-required-6odzwg5zv
og:image: https://api.daily.dev/og/posts/6ODzWG5zv.png
og:image:alt: Critical Vulnerability Patched in WPML WordPress Plugin: Immediate Update Required
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Vulnerability Patched in WPML WordPress Plugin: Immediate Update Required

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

A critical Remote Code Execution (RCE) vulnerability in the WPML WordPress plugin has been patched. With a CVSS score of 9.9, the issue affects all versions prior to 4.6.13, and users are urged to update immediately to version 4.6.13. The vulnerability allowed authenticated users with Contributor-level access to execute arbitrary code remotely. This patch is part of broader security improvements in WordPress plugins.

## Content

# Critical Vulnerability Patched in WPML WordPress Plugin: Immediate Update Required

A critical Remote Code Execution (RCE) vulnerability has been patched in the WPML WordPress plugin, which is utilized by over a million websites globally. This vulnerability, identified as CVE-2024-6386, has been rated with a CVSS score of 9.9 out of 10, underscoring its severity. The issue affects all versions of the plugin prior to 4.6.13, and users are strongly advised to update to the latest version immediately to protect their sites.

## Details of the Vulnerability

Security researcher Mat Rollings discovered the flaw, which is tied to a Twig Server-Side Template Injection due to missing input validation in the plugin's render function. This allowed authenticated users with Contributor-level access to execute arbitrary code remotely. Detailed technical aspects of the vulnerability have been shared by Rollings on his blog.

## Urgent Need for Update

The latest update, which was released on August 20, 2024, addresses this critical security issue. Users of the WPML plugin should upgrade to version 4.6.13 without delay to mitigate potential threats.

## A Broader Context of Plugin Security

This recent patch is part of a broader wave of security improvements in WordPress plugins. Researchers have received over $21,000 in bounties for identifying critical vulnerabilities in various plugins, including GiveWP, LiteSpeed Cache, and WPML. These efforts are essential in maintaining the security and integrity of the WordPress ecosystem.

In summary, website administrators are urged to ensure that their WPML plugin is up to date to defend against potential exploitation.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#wordpress](https://daily.dev/tags/wordpress), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/critical-vulnerability-patched-in-wpml-wordpress-plugin-immediate-update-required-6odzwg5zv)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical Vulnerability Patched in WPML WordPress Plugin: Immediate Update Required","url":"https://daily.dev/posts/critical-vulnerability-patched-in-wpml-wordpress-plugin-immediate-update-required-6odzwg5zv","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-vulnerability-patched-in-wpml-wordpress-plugin-immediate-update-required-6odzwg5zv"},"datePublished":"2024-08-28T12:26:42.428Z","dateModified":"2024-08-28T12:27:07.103Z","description":"A critical Remote Code Execution (RCE) vulnerability in the WPML WordPress plugin has been patched. With a CVSS score of 9.9, the issue affects all versions...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e7ec8ce62f215e5fcb2329f6b9510d47?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e7ec8ce62f215e5fcb2329f6b9510d47?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-vulnerability-patched-in-wpml-wordpress-plugin-immediate-update-required-6odzwg5zv","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,wordpress,vulnerability","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Critical Vulnerability Patched in WPML WordPress Plugin: Immediate Update Required"}]}
```

