Vulnerability Details CVE-2020-24948
The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.293
EPSS Ranking 96.4%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2020-24948
-
cpe:2.3:a:autoptimize:autoptimize:-
-
cpe:2.3:a:autoptimize:autoptimize:0.1
-
cpe:2.3:a:autoptimize:autoptimize:0.2
-
cpe:2.3:a:autoptimize:autoptimize:0.3
-
cpe:2.3:a:autoptimize:autoptimize:0.4
-
cpe:2.3:a:autoptimize:autoptimize:0.5
-
cpe:2.3:a:autoptimize:autoptimize:0.6
-
cpe:2.3:a:autoptimize:autoptimize:0.7
-
cpe:2.3:a:autoptimize:autoptimize:0.8
-
cpe:2.3:a:autoptimize:autoptimize:0.9
-
cpe:2.3:a:autoptimize:autoptimize:1.1
-
cpe:2.3:a:autoptimize:autoptimize:1.2
-
cpe:2.3:a:autoptimize:autoptimize:1.3
-
cpe:2.3:a:autoptimize:autoptimize:1.4
-
cpe:2.3:a:autoptimize:autoptimize:1.5
-
cpe:2.3:a:autoptimize:autoptimize:1.5.1
-
cpe:2.3:a:autoptimize:autoptimize:1.6.0
-
cpe:2.3:a:autoptimize:autoptimize:1.6.1
-
cpe:2.3:a:autoptimize:autoptimize:1.6.2
-
cpe:2.3:a:autoptimize:autoptimize:1.6.3
-
cpe:2.3:a:autoptimize:autoptimize:1.6.4
-
cpe:2.3:a:autoptimize:autoptimize:1.6.5
-
cpe:2.3:a:autoptimize:autoptimize:1.6.6
-
cpe:2.3:a:autoptimize:autoptimize:1.7.0
-
cpe:2.3:a:autoptimize:autoptimize:1.7.1
-
cpe:2.3:a:autoptimize:autoptimize:1.7.2
-
cpe:2.3:a:autoptimize:autoptimize:1.7.3
-
cpe:2.3:a:autoptimize:autoptimize:1.8.0
-
cpe:2.3:a:autoptimize:autoptimize:1.8.1
-
cpe:2.3:a:autoptimize:autoptimize:1.8.2
-
cpe:2.3:a:autoptimize:autoptimize:1.8.3
-
cpe:2.3:a:autoptimize:autoptimize:1.8.4
-
cpe:2.3:a:autoptimize:autoptimize:1.8.5
-
cpe:2.3:a:autoptimize:autoptimize:1.9.0
-
cpe:2.3:a:autoptimize:autoptimize:1.9.1
-
cpe:2.3:a:autoptimize:autoptimize:1.9.2
-
cpe:2.3:a:autoptimize:autoptimize:1.9.3
-
cpe:2.3:a:autoptimize:autoptimize:1.9.4
-
cpe:2.3:a:autoptimize:autoptimize:2.0.0
-
cpe:2.3:a:autoptimize:autoptimize:2.0.1
-
cpe:2.3:a:autoptimize:autoptimize:2.0.2
-
cpe:2.3:a:autoptimize:autoptimize:2.1.0
-
cpe:2.3:a:autoptimize:autoptimize:2.1.1
-
cpe:2.3:a:autoptimize:autoptimize:2.1.2
-
cpe:2.3:a:autoptimize:autoptimize:2.2.0
-
cpe:2.3:a:autoptimize:autoptimize:2.2.1
-
cpe:2.3:a:autoptimize:autoptimize:2.2.2
-
cpe:2.3:a:autoptimize:autoptimize:2.3.0
-
cpe:2.3:a:autoptimize:autoptimize:2.3.1
-
cpe:2.3:a:autoptimize:autoptimize:2.3.2
-
cpe:2.3:a:autoptimize:autoptimize:2.3.3
-
cpe:2.3:a:autoptimize:autoptimize:2.3.4
-
cpe:2.3:a:autoptimize:autoptimize:2.4.0
-
cpe:2.3:a:autoptimize:autoptimize:2.4.1
-
cpe:2.3:a:autoptimize:autoptimize:2.4.2
-
cpe:2.3:a:autoptimize:autoptimize:2.4.3
-
cpe:2.3:a:autoptimize:autoptimize:2.4.4
-
cpe:2.3:a:autoptimize:autoptimize:2.5.0
-
cpe:2.3:a:autoptimize:autoptimize:2.5.1
-
cpe:2.3:a:autoptimize:autoptimize:2.6.0
-
cpe:2.3:a:autoptimize:autoptimize:2.6.1
-
cpe:2.3:a:autoptimize:autoptimize:2.6.2
-
cpe:2.3:a:autoptimize:autoptimize:2.7.0
-
cpe:2.3:a:autoptimize:autoptimize:2.7.1
-
cpe:2.3:a:autoptimize:autoptimize:2.7.2
-
cpe:2.3:a:autoptimize:autoptimize:2.7.3
-
cpe:2.3:a:autoptimize:autoptimize:2.7.4
-
cpe:2.3:a:autoptimize:autoptimize:2.7.5
-
cpe:2.3:a:autoptimize:autoptimize:2.7.6