CVE-2024-5853: Image Optimizer, Resizer and CDN – Sirv <= 7.2.6 - Authenticated (Contributor+) Arbitrary File Upload
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirvuploadfilebychanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: “Image Optimizer, Resizer and CDN – Sirv”to a version that resolves this vulnerability.Fixed in 7.2.6 - Compensating control
If immediate upgrading is not possible, restrict authenticated access so only trusted administrators can use the WordPress account roles that can reach the Sirv plugin’s AJAX action (Contributor+).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5853?
CVE-2024-5853 has a high severity rating due to its potential for arbitrary file uploads.
What is affected by CVE-2024-5853?
CVE-2024-5853 affects the Sirv Image Optimizer, Resizer and CDN plugin for WordPress versions up to and including 7.2.6.
How do I fix CVE-2024-5853?
To fix CVE-2024-5853, update the Sirv Image Optimizer, Resizer and CDN plugin to the latest version.
Can CVE-2024-5853 be exploited remotely?
Yes, CVE-2024-5853 can be exploited remotely by authenticated attackers.
What does the vulnerability CVE-2024-5853 allow?
CVE-2024-5853 allows attackers to upload arbitrary files due to missing file type validation.