CVE · Critical

CVE-2021-24376 — Autoptimize [autoptimize] < 2.7.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24376 Autoptimize [autoptimize] < 2.7.8 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 2.7.8 2.7.8 2020-10-09

CVE-2021-24376

The Autoptimize plugin prior to version 2.7.8 contains a flaw in its "Import Settings" feature where uploaded zip archives are extracted before malicious files are deleted. While the plugin attempts to remove dangerous file types like PHP files after extraction, it fails to inspect directories within the archive, allowing an attacker to bypass these protections by nesting a PHP file inside a folder and subsequently achieve remote code execution on the server. This represents a circumvention of a previously patched vulnerability identified as CVE-2020-24948.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.