The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress has been found to have a security flaw. This vulnerability, known as Stored Cross-Site Scripting (XSS), could allow malicious code to be injected into websites using the affected plugin.
CVE Details
- Product Name: Image Optimizer, Resizer and CDN – Sirv plugin for WordPress
- Published Date: October 8, 2024
- Severity: Medium
- Status: Analyzed
Affected Products
This vulnerability affects all versions of the Image Optimizer, Resizer and CDN – Sirv plugin for WordPress up to, and including, version 7.2.9. If you are using any version within this range, your website may be at risk.
Current Status
The vulnerability has been thoroughly analyzed. Fortunately, a fix is available. Users are strongly encouraged to update their Sirv plugin to version 7.3.0 or a newer version to address this issue. The update includes important security improvements, specifically addressing the sanitization of SVG files to prevent such attacks.
Severity Level
The vulnerability is rated as Medium severity. In simple terms, this means that while exploiting it might not be extremely easy, it could still lead to significant issues. An attacker who successfully exploits this flaw could inject harmful web scripts. These scripts would then run in the browsers of other users when they access the affected SVG files. This could lead to actions like stealing sensitive information, defacing the website, or redirecting users to malicious sites.
Possible Solutions
The most critical step is to update your “Image Optimizer, Resizer and CDN – Sirv” plugin for WordPress immediately.
Sirv released version 7.3.0 which includes crucial security enhancements. This update specifically focuses on improving security measures and adding proper sanitization for SVG file uploads, which was the root cause of this vulnerability. Always ensure your WordPress plugins are up-to-date to protect your website from known security risks.
References
https://plugins.trac.wordpress.org/changeset/3162079/
https://www.wordfence.com/threat-intel/vulnerabilities/id/39b2435f-32a3-4158-a734-c21a0cab15be?source=cve


