Impact
The vulnerability is a missing authorization flaw in the Benbodhi SVG Support WordPress plugin. It arises from incorrectly configured access control security levels, allowing an attacker to bypass intended restrictions. An attacker who can interact with the plugin’s upload or edit features may upload and execute malicious SVG files, potentially leading to unauthorized content injection or even code execution if the SVG is crafted to exploit other weaknesses.
Affected Systems
The affected product is the Benbodhi SVG Support plugin for WordPress. Versions from the plugin’s initial release up through 2.5.14 are vulnerable. Any WordPress installation using these versions is exposed.
Risk and Exploitability
The CVSS score for this issue is 4.3, indicating moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that current exploitation activity is not confirmed. The likely attack vector is through the web interface of the WordPress site, though the flaw hinges on improper access control settings rather than a universal exposure. An attacker would need the ability to input data via the plugin, which could be granted to users with elevated roles if the security levels are misconfigured. The overall risk is moderate, but could become severe in deployments where high‑privilege roles are misassigned or where the plugin’s upload endpoint is exposed to untrusted users.
OpenCVE Enrichment