Description
The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15279 | The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution. |
References
History
Wed, 11 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orangelab
Orangelab imagemagick Engine |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:orangelab:imagemagick_engine:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Orangelab
Orangelab imagemagick Engine |
Tue, 20 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution. | |
| Title | ImageMagick Engine < 1.7.11 - Administrator+ OS Command Injection | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-20T19:24:28.330Z
Reserved: 2024-07-03T17:36:46.785Z
Link: CVE-2024-6486
Updated: 2025-05-19T20:27:15.397Z
Status : Analyzed
Published: 2025-05-15T20:15:55.220
Modified: 2025-06-11T15:40:01.067
Link: CVE-2024-6486
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD