peter bassill · operator
$ cve CVE-2021-24376 JSON

CVE-2021-24376

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it is not removed from the disk. It is a bypass of CVE-2020-24948 which allows sending a PHP file via the "Import Settings" functionality to achieve Remote Code Execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.73% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2021-06-21
Last modified2026-06-17

Affected (1)

VendorProduct
autoptimizeautoptimize

References

→ the Explorer  ·  watch your stack  ·  NVD