CVE-2021-24378: Autoptimize < 2.7.8 - Authenticated Stored XSS via File Upload
The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24378?
CVE-2021-24378 is considered to have a high severity due to the potential for remote code execution through malicious file uploads.
How do I fix CVE-2021-24378?
To fix CVE-2021-24378, update the Autoptimize WordPress plugin to version 2.7.8 or later.
What versions of Autoptimize are affected by CVE-2021-24378?
CVE-2021-24378 affects all versions of Autoptimize prior to 2.7.8.
What type of files can be maliciously uploaded due to CVE-2021-24378?
Due to CVE-2021-24378, a user could potentially upload malicious .html files containing JavaScript code.
Who is at risk from CVE-2021-24378?
High privilege users of the Autoptimize plugin on vulnerable WordPress installations are at risk from CVE-2021-24378.