WordPress Plugin Vulnerabilities

SVG Support < 2.5.9 - Stored Cross-Site Scripting via Vulnerability Dependency

Description

The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, and including, 2.5.8. The vulnerable dependency has a Stored Cross-Site Scripting vulnerability due to insufficient SVG sanitization. The SVG Support plugin may be exploited if the uploaded SVG image is included in line in an HTML page.

Affects Plugins

Fixed in 2.5.9

References

Classification

Type
XSS
CWE

Miscellaneous

Timeline

Publicly Published
2025-02-24 (about 1 year ago)
Added
2025-02-26 (about 1 year ago)
Last Updated
2025-02-26 (about 1 year ago)

Other