CVE-2021-24376: Autoptimize < 2.7.8 - Arbitrary File Upload via "Import Settings"
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it is not removed from the disk. It is a bypass of CVE-2020-24948 which allows sending a PHP file via the "Import Settings" functionality to achieve Remote Code Execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24376?
The severity of CVE-2021-24376 is considered high due to the potential for unauthorized file uploads and execution of malicious code.
How do I fix CVE-2021-24376?
To fix CVE-2021-24376, update the Autoptimize plugin to version 2.7.8 or later immediately.
What causes CVE-2021-24376?
CVE-2021-24376 is caused by inadequate validation of extracted files during the import process in the Autoptimize plugin.
Who is affected by CVE-2021-24376?
Any user of the Autoptimize WordPress plugin prior to version 2.7.8 is affected by CVE-2021-24376.
What impact does CVE-2021-24376 have on my WordPress site?
CVE-2021-24376 can lead to malicious file uploads, which may compromise the security of your WordPress site.