The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sirv
Sirv sirv |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:sirv:sirv:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Sirv
Sirv sirv |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T21:41:03.377Z
Reserved: 2024-06-27T16:18:22.936Z
Link: CVE-2024-6392

Updated: 2024-08-01T21:41:03.377Z

Status : Modified
Published: 2024-07-11T22:15:02.820
Modified: 2024-11-21T09:49:33.967
Link: CVE-2024-6392

No data.