CVE-2024-6486: ImageMagick Engine < 1.7.11 - Administrator+ OS Command Injection
The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "clipath" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6486?
CVE-2024-6486 has a high severity rating due to the potential for OS Command Injection by authenticated attackers.
How do I fix CVE-2024-6486?
To remedy CVE-2024-6486, update the ImageMagick Engine WordPress plugin to version 1.7.11 or later.
Who is affected by CVE-2024-6486?
CVE-2024-6486 affects users of the ImageMagick Engine for WordPress prior to version 1.7.11.
What can attackers achieve with CVE-2024-6486?
Attackers exploiting CVE-2024-6486 can execute arbitrary OS commands on the server, compromising its security.
Is authentication required to exploit CVE-2024-6486?
Yes, exploitation of CVE-2024-6486 requires administrator-level permission to perform the OS Command Injection.