Cheat sheets

CVE-2020-24948: WordPress vulnerability

Share this with people that should know this:

The ao_ccss_import AJAX call in Autoptimize WordPress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

References

  • wpvulndb.com/vulnerabilities/10372
  • Share this with people that should know this: