Uncovering a Critical File Upload Flaw in Sirv WordPress Plugin
A serious security flaw, identified as CVE-2024-5853, has been discovered in the Sirv plugin for WordPress. This vulnerability allows attackers to upload malicious files to affected websites, potentially leading to complete control over the site.
CVE Details
Product: Sirv plugin for WordPress
Published: June 19, 2024
Severity: CRITICAL (CVSS Score: 9.9)
Status: Analyzed
Affected Products
This critical vulnerability impacts all versions of the Sirv plugin for WordPress up to, and including, 7.2.6. If you are using an older version of the plugin, your website could be at significant risk.
Current Status
The vulnerability has been addressed. Sirv released version 7.2.7 of their plugin on June 17, 2024, which includes fixes for this issue. The status of this CVE is currently "Analyzed", meaning the details have been reviewed and accepted.
Severity Level
Rated as CRITICAL with a CVSS score of 9.9, this vulnerability poses a severe threat. It allows authenticated attackers, even those with low-privilege Contributor accounts, to upload arbitrary files due to a lack of proper file type validation. This could enable an attacker to execute malicious code on your server, compromise your website data, or even take over your entire site.
Possible Solutions
The most important step you can take to protect your WordPress site is to update the Sirv plugin immediately. Upgrade to version 7.2.7 or a newer release. This update includes crucial file type validation that prevents unauthorized file uploads, patching the vulnerability effectively.
References
https://plugins.trac.wordpress.org/changeset/3103410/sirv/trunk/sirv.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/e89b40ec-1952-46e3-a91b-bd38e62f8929?source=cve


