CVE-2021-24376
The Autoptimize plugin prior to version 2.7.8 contains a flaw in its "Import Settings" feature where uploaded zip archives are extracted before malicious files are deleted. While the plugin attempts to remove dangerous file types like PHP files after extraction, it fails to inspect directories within the archive, allowing an attacker to bypass these protections by nesting a PHP file inside a folder and subsequently achieve remote code execution on the server. This represents a circumvention of a previously patched vulnerability identified as CVE-2020-24948.
Based on public CVE data (MITRE/NVD).