← WordPress Vulnerabilities
WordPress security by component

Sirv

Sirv is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Apr 22, 2025; the highest CVE/CNA score is 9.9.

Plugin slug: sirv

CVE-2025-46233: Sirv: Cross-site scripting

Sirv is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedApr 22, 2025
Safe version guidanceSee mitigation notes
Safe version
Apr 22, 2025 CVE-2025-46233
Sirv: Cross-site scripting
Sirv is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Nov 20, 2024 CVE-2024-10855
Image Optimizer, Resizer and CDN – Sirv: A security weakness
Image Optimizer, Resizer and CDN – Sirv is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVDPending
Oct 08, 2024 CVE-2024-8964
Image Optimizer, Resizer and CDN – Sirv: Cross-site scripting
Image Optimizer, Resizer and CDN – Sirv is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 06, 2024 CVE-2024-8480
Image Optimizer, Resizer and CDN – Sirv: Code execution
Image Optimizer, Resizer and CDN – Sirv is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Jul 11, 2024 CVE-2024-6392
Image Optimizer, Resizer and CDN – Sirv: A security weakness
Image Optimizer, Resizer and CDN – Sirv is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jun 19, 2024 CVE-2024-5853
Image Optimizer, Resizer and CDN – Sirv: Dangerous file upload
Image Optimizer, Resizer and CDN – Sirv is affected by dangerous file upload. Exploitation requires at least contributor-level access. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.9
NVD8.8
May 17, 2024 CVE-2024-32959
Sirv: A security weakness
Sirv is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVDPending
Mar 15, 2024 CVE-2023-50898
Sirv: A security weakness
Sirv is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD8.8
Mar 01, 2024 CVE-2024-27950
Sirv: A security weakness
Sirv is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD8.8
Mar 01, 2024 CVE-2024-27949
Sirv: Server-side request forgery
Sirv is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.4
NVDPending
Sep 13, 2019 CVE-2016-10950
Sirv: SQL injection
Sirv is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8