vendor:
Autoptimize
by:
SunCSR Team
8.8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Autoptimize
Affected Version From: 2.7.6
Affected Version To: 2.7.6
Patch Exists: YES
Related CWE: N/A
CPE: 2.7.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04 / Kali Linux
2020
WordPress Plugin Autoptimize 2.7.6 – Arbitrary File Upload (Authenticated)
The ao_ccss_import AJAX call does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE.
Mitigation:
Ensure that the file provided is a legitimate Zip file.