ImageMagick Engine < 1.7.11 - Administrator+ OS Command Injection
Description
Authenticated administrators can inject OS commands via the cli_path parameter in ImageMagick Engine before 1.7.11, leading to RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated administrators can inject OS commands via the cli_path parameter in ImageMagick Engine before 1.7.11, leading to RCE.
Vulnerability
The ImageMagick Engine WordPress plugin versions before 1.7.11 are vulnerable to OS command injection through the cli_path parameter. The plugin fails to properly sanitize user-supplied input used in command execution, allowing arbitrary command injection. The vulnerability exists in the administrative interface and requires the attacker to have administrator-level permissions on the WordPress site [1].
Exploitation
An authenticated attacker with administrative access can exploit this vulnerability by manipulating the cli_path parameter in a request processed by the plugin. The attacker does not need any additional privileges beyond administrator-level access. The exact steps involve sending a crafted request where the cli_path parameter contains malicious OS command payloads, which are then executed by the plugin [1].
Impact
Successful exploitation allows the attacker to execute arbitrary operating system commands on the server, leading to remote code execution (RCE). This can result in full compromise of the WordPress site, including data theft, site defacement, or further pivoting within the hosting environment. The impact is critical as it provides administrator-equivalent or greater control over the server [1].
Mitigation
The vulnerability is fixed in version 1.7.11 of the ImageMagick Engine plugin. Users should update to this version immediately. There is no known workaround provided in the advisory. The plugin repository and advisory confirm the fixed version [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)
- Range: <1.7.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/a57c0c59-8b5c-4221-a9db-19f141650d9b/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.