Autoptimize < 2.7.8 - Authenticated Stored XSS via File Upload
CVE-2021-24378

4.8MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 June 2021

Summary

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

Affected Version(s)

Autoptimize 2.7.8

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcin Węgłowski
.