CVE-2024-27950: WordPress Sirv plugin <= 7.2.0 - Broken Access Control vulnerability
Published Mar 1, 2024
·Updated
Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.
Affected Software
5 affected components
Sirv Image Optimizer<=7.2.0
Sirv Resizer<=7.2.0
Sirv CDN<=7.2.0
WordPress Sirv Plugin<=7.2.0
Sirv Sirv Wordpress<7.2.1
Remediation
Information
Update to 7.2.1 or a higher version.
Event History
Mar 1, 2024
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27950?
CVE-2024-27950 is categorized as a missing authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2024-27950?
To fix CVE-2024-27950, you should upgrade all affected Sirv products to a version higher than 7.2.0.
3
Which products are affected by CVE-2024-27950?
CVE-2024-27950 affects Sirv Image Optimizer, Resizer, CDN, and the WordPress Sirv Plugin versions up to and including 7.2.0.
4
What are the potential risks associated with CVE-2024-27950?
The risks associated with CVE-2024-27950 include unauthorized access to image resources and potential data exposure.
5
Is there a workaround for CVE-2024-27950?
Currently, the recommended solution for CVE-2024-27950 is to update the software, as no specific workarounds have been published.