The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47499 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 15 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sirv
Sirv sirv |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:sirv:sirv:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Sirv
Sirv sirv |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T21:41:03.377Z
Reserved: 2024-06-27T16:18:22.936Z
Link: CVE-2024-6392
Updated: 2024-08-01T21:41:03.377Z
Status : Modified
Published: 2024-07-11T22:15:02.820
Modified: 2024-11-21T09:49:33.967
Link: CVE-2024-6392
No data.
OpenCVE Enrichment
No data.
EUVD