Security Research

CVE-2024-22144 WordPress GOTMLS Plugin Code Injection: a 200k-install string concatenation bug

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of WordPress plugin and unfiltered string concatenation

The WordPress GOTMLS plugin (200k+ active installs) does not parameterize user input. An attacker can run arbitrary PHP on the server through simple string concatenation.

Unlock to view this content.