CVE-2020-24948: Malicious File Upload
Published Sep 3, 2020
·Updated
The aoccssimport AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
Affected Software
1 affected component
Autoptimize Autoptimize Wordpress<2.7.7
Event History
Sep 3, 2020
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24948?
CVE-2020-24948 has a high severity level due to the potential for remote command execution.
2
How do I fix CVE-2020-24948?
To fix CVE-2020-24948, update the Autoptimize plugin to version 2.7.7 or later.
3
What types of files can be uploaded due to CVE-2020-24948?
CVE-2020-24948 allows for the upload of arbitrary files, including PHP scripts.
4
Which versions of the Autoptimize plugin are affected by CVE-2020-24948?
CVE-2020-24948 affects Autoptimize plugin versions prior to 2.7.7.
5
Who is at risk from CVE-2020-24948?
High privilege users of WordPress sites using the vulnerable version of the Autoptimize plugin are at risk.