WordPress Plugin Vulnerabilities
SVG Support < 2.5.9 - Stored Cross-Site Scripting via Vulnerability Dependency
Description
The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, and including, 2.5.8. The vulnerable dependency has a Stored Cross-Site Scripting vulnerability due to insufficient SVG sanitization. The SVG Support plugin may be exploited if the uploaded SVG image is included in line in an HTML page.
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Verified
No
WPVDB ID
Timeline
Publicly Published
2025-02-24 (about 1 year ago)
Added
2025-02-26 (about 1 year ago)
Last Updated
2025-02-26 (about 1 year ago)