The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0002}

epss

{'score': 0.00022}


Tue, 24 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Wp Enable Svg Project
Wp Enable Svg Project wp Enable Svg
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wp_enable_svg_project:wp_enable_svg:*:*:*:*:*:wordpress:*:*
Vendors & Products Wp Enable Svg Project
Wp Enable Svg Project wp Enable Svg

Mon, 06 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jan 2025 06:15:00 +0000

Type Values Removed Values Added
Description The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts
Title WP Enabled SVG <= 0.7 - Author+ Stored XSS via SVG
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-01-06T20:30:08.869Z

Reserved: 2024-11-13T15:55:57.036Z

Link: CVE-2024-11184

cve-icon Vulnrichment

Updated: 2025-01-06T20:30:02.676Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-02T06:15:06.697

Modified: 2025-06-24T00:21:37.557

Link: CVE-2024-11184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.