CVE-2024-8480: Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirvsavepreventedsizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to exploit the 'sirvuploadfilebychunkscallback' function, which lacks proper file type validation, allowing attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8480?
CVE-2024-8480 has a moderate severity as it allows unauthorized data modification by authenticated users.
How do I fix CVE-2024-8480?
To fix CVE-2024-8480, update the Sirv plugin for WordPress to version 7.2.8 or later.
Who is affected by CVE-2024-8480?
CVE-2024-8480 affects all versions of the Sirv plugin for WordPress up to and including version 7.2.7.
What functions are related to CVE-2024-8480?
The vulnerability in CVE-2024-8480 is related to the 'sirv_save_prevented_sizes' function.
What type of attacks can exploit CVE-2024-8480?
CVE-2024-8480 can be exploited by authenticated attackers to modify data without proper authorization.