Sirv <= 7.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will e...
- CVSS:
- 6.4
- Affected:
- up to 7.5.3
- Fixed in:
- 7.5.4
- Disclosed:
- Apr 22, 2025
CVE-2025-46233 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.5.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3.
- Affected:
- up to 7.5.4
- Fixed in:
- 7.5.4
- Disclosed:
- Apr 22, 2025
CVE-2025-46233 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.3.1
unknown
[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. Th...
- Affected:
- up to 7.3.1
- Fixed in:
- 7.3.1
- Disclosed:
- Nov 20, 2024
CVE-2024-10855 on NVD →
Image Optimizer, Resizer and CDN – Sirv <= 7.3.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Option Deletion
high
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. This ma...
- CVSS:
- 8.1
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.1
- Disclosed:
- Nov 19, 2024
CVE-2024-10855 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.3.0
unknown
[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and...
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Oct 8, 2024
CVE-2024-8964 on NVD →
Image Optimizer, Resizer and CDN – Sirv <= 7.2.9 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 7.2.9
- Fixed in:
- 7.3.0
- Disclosed:
- Oct 7, 2024
CVE-2024-8964 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.8
unknown
[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level a...
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.8
- Disclosed:
- Sep 6, 2024
CVE-2024-8480 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.8
unknown
<p>WordPress Sirv Plugin <= 7.2.7 is vulnerable to Arbitrary File Upload</p><p>Software: Sirv</p><p>Link: https://wordpress.org/plugins/sirv/#developers</p><p>Affected Version <= 7.2.7</p><p>Fixed in version 7.2.8 </p>
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.8
- Disclosed:
- Aug 22, 2024
Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload
high
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access...
- CVSS:
- 8.8
- Affected:
- up to 7.2.7
- Fixed in:
- 7.2.8
- Disclosed:
- Aug 21, 2024
CVE-2024-8480 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.8
unknown
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access...
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.8
- Disclosed:
- Aug 21, 2024
Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Authenticated(Subscriber+) Missing Authorization to Plugin Settings Update
medium
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
- CVSS:
- 5.4
- Affected:
- up to 7.2.7
- Fixed in:
- 7.2.8
- Disclosed:
- Jul 11, 2024
CVE-2024-6392 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.8
unknown
[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and abov...
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.8
- Disclosed:
- Jul 11, 2024
CVE-2024-6392 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.7
unknown
[en] The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access a...
- Affected:
- up to 7.2.7
- Fixed in:
- 7.2.7
- Disclosed:
- Jun 19, 2024
CVE-2024-5853 on NVD →
Image Optimizer, Resizer and CDN – Sirv <= 7.2.6 - Authenticated (Contributor+) Arbitrary File Upload
critical
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and ab...
- CVSS:
- 9.9
- Affected:
- up to 7.2.6
- Fixed in:
- 7.2.7
- Disclosed:
- Jun 18, 2024
CVE-2024-5853 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.3
unknown
[en] Improper Privilege Management vulnerability in Sirv allows Privilege Escalation.This issue affects Sirv: from n/a through 7.2.2.
- Affected:
- up to 7.2.3
- Fixed in:
- 7.2.3
- Disclosed:
- May 17, 2024
CVE-2024-32959 on NVD →
Sirv <= 7.2.2 - Missing Authorization to Arbitrary Options Update
critical
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sirv_dismiss_notice() function in all versions up to, and including, 7.2.2. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 9.8
- Affected:
- up to 7.2.2
- Fixed in:
- 7.2.3
- Disclosed:
- Apr 23, 2024
CVE-2024-32959 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.1.3
unknown
[en] Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.
- Affected:
- up to 7.1.3
- Fixed in:
- 7.1.3
- Disclosed:
- Mar 15, 2024
CVE-2023-50898 on NVD →
Image Optimizer, Resizer and CDN – Sirv <= 7.2.0 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web appl...
- CVSS:
- 6.4
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 1, 2024
CVE-2024-27949 on NVD →
Image Optimizer, Resizer and CDN – Sirv <= 7.2.0 - Missing Authorization
medium
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including 7.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 1, 2024
CVE-2024-27950 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.1
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0.
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 1, 2024
CVE-2024-27949 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 7.2.1
unknown
[en] Missing Authorization vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0.
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 1, 2024
CVE-2024-27950 on NVD →
Sirv <= 7.1.2 - Missing Authorization via sirv_disconnect
medium
The Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sirv_disconnect function hooked via AJAX in versions up to, and including, 7.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to disconnect the sites...
- CVSS:
- 4.3
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.3
- Disclosed:
- Dec 26, 2023
CVE-2023-50898 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 6.8.1
unknown
[en] The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
- Disclosed:
- Jan 2, 2023
CVE-2022-4119 on NVD →
Image Optimizer, Resizer and CDN – Sirv <= 6.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘SIRV_ACCOUNT_EMAIL’ parameter in versions up to, and including, 6.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...
- CVSS:
- 5.5
- Affected:
- up to 6.8.0
- Fixed in:
- 6.8.1
- Disclosed:
- Dec 9, 2022
CVE-2022-4119 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 1.3.2
unknown
[en] The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Sep 13, 2019
CVE-2016-10950 on NVD →
Image Optimizer, Resizer and CDN – Sirv < 1.3.2 - SQL Injection
high
The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
- CVSS:
- 8.8
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Nov 10, 2016
CVE-2016-10950 on NVD →
Image Optimizer, Resizer and CDN – Sirv [sirv] < 1.3.2
unknown
This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Nov 10, 2016