The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sirv
Sirv sirv |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:sirv:sirv:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Sirv
Sirv sirv |
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-07-11T21:31:34.282Z
Updated: 2024-08-01T21:41:03.377Z
Reserved: 2024-06-27T16:18:22.936Z
Link: CVE-2024-6392
Vulnrichment
Updated: 2024-08-01T21:41:03.377Z
NVD
Status : Modified
Published: 2024-07-11T22:15:02.820
Modified: 2024-11-21T09:49:33.967
Link: CVE-2024-6392
Redhat
No data.