cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsirv sirv

Direction: descending
Jun 16, 2026

Image Optimizer, Resizer and CDN – Sirv # 8b813f28f58358cb71cea41dfabc7b6f20695e6a

Date
Aug 21, 2024
Research Description
Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.8 Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to exploit the 'sirv_upload_file_by_chunks_callback' function, which lacks proper file type validation, allowing attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
max 7.2.8.
Status
vulnerable

Image Optimizer, Resizer and CDN &#8211; Sirv # 92885f0851f32f994845a1c9235b680a0694e3b5

Date
Aug 22, 2024
Research Description
Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 7.2.8 WordPress Sirv Plugin <= 7.2.7 is vulnerable to Arbitrary File Upload <p>WordPress Sirv Plugin <= 7.2.7 is vulnerable to Arbitrary File Upload</p><p>Software: Sirv</p><p>Link: https://wordpress.org/plugins/sirv/#developers</p><p>Affected Version <= 7.2.7</p><p>Fixed in version 7.2.8 </p>
Affected versions
max 7.2.8.
Status
vulnerable

Image Optimizer, Resizer and CDN &#8211; Sirv # 4fa128f4a5f2fa813ecec329478179fef8e2ece2

Date
Nov 10, 2016
Research Description
Image Optimizer, Resizer and CDN &#8211; Sirv [sirv] < 1.3.2 WordPress Sirv Plugin <= 1.3.1 - Authenticated SQL Injection This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.
Affected versions
max 1.3.2.
Status
vulnerable
Apr 23, 2025

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2025-46233

CVE, Research URL

CVE-2025-46233

Date
Apr 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: from n/a through <= 7.5.3.
Affected versions
max 7.5.4.
Status
vulnerable
Nov 21, 2024

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-10855

CVE, Research URL

CVE-2024-10855

Date
Nov 20, 2024
Research Description
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users.
Affected versions
max 7.3.1.
Status
vulnerable
Oct 09, 2024

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-8964

CVE, Research URL

CVE-2024-8964

Date
Oct 08, 2024
Research Description
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected versions
max 7.3.0.
Status
vulnerable
Sep 08, 2024

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-8480

CVE, Research URL

CVE-2024-8480

Date
Sep 06, 2024
Research Description
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to exploit the 'sirv_upload_file_by_chunks_callback' function, which lacks proper file type validation, allowing attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
max 7.2.8.
Status
vulnerable
Jul 13, 2024

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-6392

CVE, Research URL

CVE-2024-6392

Date
Jul 12, 2024
Research Description
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one.
Affected versions
max 7.2.8.
Status
vulnerable
Jun 20, 2024

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-5853

CVE, Research URL

CVE-2024-5853

Date
Jun 19, 2024
Research Description
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
max 7.2.7.
Status
vulnerable
Jun 07, 2024

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-32959

CVE, Research URL

CVE-2024-32959

Date
May 17, 2024
Research Description
Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.
Affected versions
max 7.2.3.
Status
vulnerable

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2016-10950

CVE, Research URL

CVE-2016-10950

Date
Sep 13, 2019
Research Description
The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
Affected versions
max 1.3.2.
Status
vulnerable

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2022-4119

CVE, Research URL

CVE-2022-4119

Date
Jan 03, 2023
Research Description
The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 6.8.1.
Status
vulnerable

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2023-50898

CVE, Research URL

CVE-2023-50898

Date
Mar 15, 2024
Research Description
Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.
Affected versions
max 7.1.3.
Status
vulnerable

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-27949

CVE, Research URL

CVE-2024-27949

Date
Mar 01, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.
Affected versions
max 7.2.1.
Status
vulnerable

Image Optimizer, Resizer and CDN &#8211; Sirv # CVE-2024-27950

CVE, Research URL

CVE-2024-27950

Date
Mar 01, 2024
Research Description
Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.
Affected versions
max 7.2.1.
Status
vulnerable