The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sterlinghamilton
Sterlinghamilton scalable Vector Graphics \(svg\) |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:sterlinghamilton:scalable_vector_graphics_\(svg\):*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Sterlinghamilton
Sterlinghamilton scalable Vector Graphics \(svg\) |
Wed, 28 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-28T15:36:59.154Z
Reserved: 2023-12-22T19:40:02.769Z
Link: CVE-2023-7085
Updated: 2024-08-02T08:50:07.997Z
Status : Analyzed
Published: 2024-03-18T19:15:06.160
Modified: 2025-05-05T18:00:58.713
Link: CVE-2023-7085
No data.
OpenCVE Enrichment
No data.
Weaknesses