The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one.
History

Thu, 15 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sirv
Sirv sirv
Weaknesses CWE-862
CPEs cpe:2.3:a:sirv:sirv:*:*:*:*:*:wordpress:*:*
Vendors & Products Sirv
Sirv sirv

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-07-11T21:31:34.282Z

Updated: 2024-08-01T21:41:03.377Z

Reserved: 2024-06-27T16:18:22.936Z

Link: CVE-2024-6392

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:03.377Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-11T22:15:02.820

Modified: 2024-08-15T14:56:16.490

Link: CVE-2024-6392

cve-icon Redhat

No data.