S4E just found a low dns any record query
critical·Product Based Web Vulnerabilities·Updated Dec 10, 2024

CVE-2024-10516 Scanner

CVE-2024-10516 Scanner - Local File Inclusion (LFI) vulnerability in Swift Performance Lite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-10516
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Swift Performance Liteby swte
0
swift_performanceby swteplugins
0
Updated Aug 22, 2026View on NVD →
Detail

Swift Performance Lite is a popular WordPress plugin used to enhance website speed and performance. It is widely utilized by website administrators and developers to optimize web content delivery and improve user experience. The plugin offers caching, image optimization, and database cleanup functionalities to boost website efficiency.

The vulnerability in Swift Performance Lite allows unauthenticated attackers to exploit the 'ajaxify' parameter for Local PHP File Inclusion. This flaw can potentially be used to access or include unintended files on the server. Affected versions are prone to exploitation, making it crucial to address this issue promptly.

Technical details indicate that the vulnerable parameter 'ajaxify' can be manipulated to include local PHP files via maliciously crafted requests. Attackers may leverage this to execute arbitrary PHP code on the server, significantly compromising its integrity and security.

If exploited, this vulnerability could lead to unauthorized access, sensitive information disclosure, and complete server takeover. These effects pose severe risks to data confidentiality, integrity, and availability.

REFERENCES

Solution Advice
  • Update Swift Performance Lite to version 2.3.7.2 or later to fix the vulnerability.
  • Regularly monitor and apply security patches for WordPress plugins.
  • Restrict access to administrative endpoints to trusted users and networks only.
  • Enable logging to detect suspicious activity involving vulnerable endpoints.
  • Conduct periodic security audits to identify and address vulnerabilities in plugins and configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.