CVE-2024-4636: Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF <= 3.12.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘allowmemetypes’ function in versions up to, and including, 3.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIFto a version that resolves this vulnerability.Fixed in 3.12.10 - Compensating control
Restrict access to the WordPress account roles that have contributor-level permissions and above until the plugin is upgraded/fixed, to reduce risk from authenticated attackers exploiting the stored XSS upload path.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4636?
The severity of CVE-2024-4636 is assessed as high due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2024-4636?
To fix CVE-2024-4636, update the Optimole Image Optimization plugin to version 3.12.11 or later.
What versions are affected by CVE-2024-4636?
CVE-2024-4636 affects versions of the Optimole Image Optimization plugin up to and including 3.12.10.
What is the impact of CVE-2024-4636?
The impact of CVE-2024-4636 includes the potential for attackers to execute arbitrary JavaScript in the context of the user's session.
Who is affected by CVE-2024-4636?
Users of the Optimole Image Optimization plugin for WordPress who are running versions 3.12.10 or earlier are affected by CVE-2024-4636.