CVE-2024-32959: WordPress Sirv plugin <= 7.2.2 - Arbitrary Option Update to Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.
Affected Software
3 affected components
Sirv Sirv>=n/a, <=7.2.2
WordPress Sirv Plugin<=7.2.2
Sirv Sirv Wordpress<7.2.3
Remediation
Information
Update to 7.2.3 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·09:40 AM
Data Sourced
via MITRE·09:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32959?
CVE-2024-32959 is classified as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-32959?
To fix CVE-2024-32959, upgrade the Sirv application or WordPress Sirv plugin to a version higher than 7.2.2.
3
Who is affected by CVE-2024-32959?
CVE-2024-32959 affects Sirv versions from n/a through 7.2.2 and the WordPress Sirv plugin up to version 7.2.2.
4
What type of vulnerability is CVE-2024-32959?
CVE-2024-32959 is an improper privilege management vulnerability that allows privilege escalation.
5
Can CVE-2024-32959 be exploited remotely?
Yes, CVE-2024-32959 can potentially be exploited remotely if the affected software is improperly configured.