plugin

Sirv Vulnerabilities

27 known security issues reported for the Sirv WordPress plugin. Most recent disclosed Apr 22, 2025.

2 critical 3 high 7 medium

Running Sirv on your site? Check whether your installed version is affected.

Scan your site free

Sirv <= 7.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will e...

CVSS:
6.4
Affected:
up to 7.5.3
Fixed in:
7.5.4
Disclosed:
Apr 22, 2025

CVE-2025-46233 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.5.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3.

Affected:
up to 7.5.4
Fixed in:
7.5.4
Disclosed:
Apr 22, 2025

CVE-2025-46233 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.3.1

unknown

[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. Th...

Affected:
up to 7.3.1
Fixed in:
7.3.1
Disclosed:
Nov 20, 2024

CVE-2024-10855 on NVD →

Image Optimizer, Resizer and CDN – Sirv <= 7.3.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Option Deletion

high

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. This ma...

CVSS:
8.1
Affected:
up to 7.3.0
Fixed in:
7.3.1
Disclosed:
Nov 19, 2024

CVE-2024-10855 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.3.0

unknown

[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and...

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Oct 8, 2024

CVE-2024-8964 on NVD →

Image Optimizer, Resizer and CDN – Sirv <= 7.2.9 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abov...

CVSS:
6.4
Affected:
up to 7.2.9
Fixed in:
7.3.0
Disclosed:
Oct 7, 2024

CVE-2024-8964 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.8

unknown

[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level a...

Affected:
up to 7.2.8
Fixed in:
7.2.8
Disclosed:
Sep 6, 2024

CVE-2024-8480 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.8

unknown

<p>WordPress Sirv Plugin <= 7.2.7 is vulnerable to Arbitrary File Upload</p><p>Software: Sirv</p><p>Link: https://wordpress.org/plugins/sirv/#developers</p><p>Affected Version <= 7.2.7</p><p>Fixed in version 7.2.8 </p>

Affected:
up to 7.2.8
Fixed in:
7.2.8
Disclosed:
Aug 22, 2024

Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload

high

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access...

CVSS:
8.8
Affected:
up to 7.2.7
Fixed in:
7.2.8
Disclosed:
Aug 21, 2024

CVE-2024-8480 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.8

unknown

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access...

Affected:
up to 7.2.8
Fixed in:
7.2.8
Disclosed:
Aug 21, 2024

Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Authenticated(Subscriber+) Missing Authorization to Plugin Settings Update

medium

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

CVSS:
5.4
Affected:
up to 7.2.7
Fixed in:
7.2.8
Disclosed:
Jul 11, 2024

CVE-2024-6392 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.8

unknown

[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and abov...

Affected:
up to 7.2.8
Fixed in:
7.2.8
Disclosed:
Jul 11, 2024

CVE-2024-6392 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.7

unknown

[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access a...

Affected:
up to 7.2.7
Fixed in:
7.2.7
Disclosed:
Jun 19, 2024

CVE-2024-5853 on NVD →

Image Optimizer, Resizer and CDN – Sirv <= 7.2.6 - Authenticated (Contributor+) Arbitrary File Upload

critical

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and ab...

CVSS:
9.9
Affected:
up to 7.2.6
Fixed in:
7.2.7
Disclosed:
Jun 18, 2024

CVE-2024-5853 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.3

unknown

[en] Improper Privilege Management vulnerability in Sirv allows Privilege Escalation.This issue affects Sirv: from n/a through 7.2.2.

Affected:
up to 7.2.3
Fixed in:
7.2.3
Disclosed:
May 17, 2024

CVE-2024-32959 on NVD →

Sirv <= 7.2.2 - Missing Authorization to Arbitrary Options Update

critical

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sirv_dismiss_notice() function in all versions up to, and including, 7.2.2. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
9.8
Affected:
up to 7.2.2
Fixed in:
7.2.3
Disclosed:
Apr 23, 2024

CVE-2024-32959 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.1.3

unknown

[en] Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
Mar 15, 2024

CVE-2023-50898 on NVD →

Image Optimizer, Resizer and CDN – Sirv <= 7.2.0 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web appl...

CVSS:
6.4
Affected:
up to 7.2.0
Fixed in:
7.2.1
Disclosed:
Mar 1, 2024

CVE-2024-27949 on NVD →

Image Optimizer, Resizer and CDN – Sirv <= 7.2.0 - Missing Authorization

medium

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including 7.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 7.2.0
Fixed in:
7.2.1
Disclosed:
Mar 1, 2024

CVE-2024-27950 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.1

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0.

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Mar 1, 2024

CVE-2024-27949 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.1

unknown

[en] Missing Authorization vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0.

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Mar 1, 2024

CVE-2024-27950 on NVD →

Sirv <= 7.1.2 - Missing Authorization via sirv_disconnect

medium

The Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sirv_disconnect function hooked via AJAX in versions up to, and including, 7.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to disconnect the sites...

CVSS:
4.3
Affected:
up to 7.1.2
Fixed in:
7.1.3
Disclosed:
Dec 26, 2023

CVE-2023-50898 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 6.8.1

unknown

[en] The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 6.8.1
Fixed in:
6.8.1
Disclosed:
Jan 2, 2023

CVE-2022-4119 on NVD →

Image Optimizer, Resizer and CDN – Sirv <= 6.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘SIRV_ACCOUNT_EMAIL’ parameter in versions up to, and including, 6.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...

CVSS:
5.5
Affected:
up to 6.8.0
Fixed in:
6.8.1
Disclosed:
Dec 9, 2022

CVE-2022-4119 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 1.3.2

unknown

[en] The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Sep 13, 2019

CVE-2016-10950 on NVD →

Image Optimizer, Resizer and CDN – Sirv < 1.3.2 - SQL Injection

high

The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.

CVSS:
8.8
Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Nov 10, 2016

CVE-2016-10950 on NVD →

Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 1.3.2

unknown

This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Nov 10, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database