CVE · High

CVE-2020-24948 — Autoptimize [autoptimize] < 2.7.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-24948 Autoptimize [autoptimize] < 2.7.7 Unrestricted Upload of File with Dangerous Type High 7.2 < 2.7.7 2.7.7 2020-08-24

CVE-2020-24948

The Autoptimize WordPress plugin prior to version 2.7.7 contains a vulnerability in the ao_ccss_import AJAX function that fails to validate whether uploaded files are genuine Zip archives. This lack of validation allows administrators and other high-privilege users to upload malicious files, including PHP scripts, which can be executed on the server to achieve remote code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.