CVE · Medium

CVE-2021-24378 — Autoptimize [autoptimize] < 2.7.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24378 Autoptimize [autoptimize] < 2.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.7.8 2.7.8 2020-10-09

CVE-2021-24378

The Autoptimize plugin before version 2.7.8 fails to validate file types within archives uploaded through its Import Settings functionality. This oversight allows authenticated users with elevated privileges to embed malicious files like HTML documents containing JavaScript into an archive, which subsequently executes when users access the resulting file within the plugin's directory. The vulnerability requires high-level user access but poses a cross-site scripting risk through the imported archive contents.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.