cleantalk
Vulnerabilities and Security Researches

ImageMagick Engine, CVE-2024-6486

CVE, Research URL

CVE-2024-6486

Application

ImageMagick Engine

Published on
May 16, 2025
Research Description
The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.
Affected versions
Min -, max 1.7.11.
Status
vulnerable