CVE-2024-6386 - Wordpress WPML (WordPress Multilingual Plugin) ≤ 4.6.12. RCE Exploit 0Day (300K Sites Vulnerability) -- Telegram: @bl4ckhatx
<h1 align="left">CVE-2024-6386 - Remote Code Execution in WPML Plugin - <a href="https://t.me/bl4ckhatx" target="_blank">
@bl4ckhatx
</a></h1>
<a href="https://t.me/bl4ckhatx" target="_blank">
<img src="https://raw.githubusercontent.com/maurodesouza/profile-readme-generator/master/src/assets/icons/social/telegram/default.svg" width="52" height="40" alt="telegram logo" />
</a>
<h3 align="left">CVE-2024-6386 - Wordpress WPML (WordPress Multilingual Plugin) ≤ 4.6.12. RCE Exploit 0Day (300K Sites Vulnerability) -- Telegram: @bl4ckhatx
</h3>
<div align="center">
<img src="poc.png" />
</div>
<a href="https://t.me/bl4ckhatx" target="_blank">
<img src="https://raw.githubusercontent.com/maurodesouza/profile-readme-generator/master/src/assets/icons/social/telegram/default.svg" width="52" height="40" alt="telegram logo" />
</a>
<h2 align="left">🎯 CVE-2024-6386: WPML RCE Exploit - <a href="https://t.me/bl4ckhatx" target="_blank">
@bl4ckhatx
</a></h2>
###
<p align="left">Zero-day RCE in WPML. All versions ≤ 4.6.12. Leverage a Twig SSTI flaw to own the server. Quick, brutal, and undetectable.</p>
###
<h2 align="left">Overview - CVE-2024-6386 - <a href="https://t.me/bl4ckhatx" target="_blank">
@bl4ckhatx
</a></h2>
###
<p align="left">This repository contains a zero-day exploit for CVE-2024-6386, targeting the WPML (WordPress Multilingual Plugin). The exploit leverages a Server-Side Template Injection vulnerability in the Twig engine, present in all WPML versions up to and including 4.6.12. With minimal effort, attackers can execute arbitrary code on the server, making it a powerful tool for anyone looking to gain unauthorized access.</p>
###
<h3 align="left">For more details or to secure a customized exploit kit, reach out on Telegram: <a href="https://t.me/bl4ckhatx" target="_blank">
@bl4ckhatx
</a></h3>
###
<div align="left">
<a href="https://t.me/bl4ckhatx" target="_blank">
<img src="https://raw.githubusercontent.com/maurodesouza/profile-readme-generator/master/src/assets/icons/social/telegram/default.svg" width="52" height="40" alt="telegram logo" />
</a>
</div>
###
[4.0K] /data/pocs/ce21c33ffead96ec22f46ea01e0ea562ed7d1acf
├── [ 18K] poc.png
└── [2.1K] README.md
0 directories, 2 files