CVE-2024-6486

HIGH

ImageMagick Engine <1.7.11 - Command Injection

Title source: llm
STIX 2.1

Description

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/a57c0c59-8b5c-4221-a9db-19f141650d9b/

Scores

CVSS v3 7.2
EPSS 0.0213
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
orangelab/imagemagick_engine < 1.7.11
Published May 15, 2025
Tracked Since Feb 18, 2026