CVE-2023-7086

The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ablyperu:svg_uploads_support:*:*:*:*:*:wordpress:*:*

History

12 Jun 2025, 14:06

Type Values Removed Values Added
CWE CWE-79
First Time Ablyperu svg Uploads Support
Ablyperu
References () https://wpscan.com/vulnerability/94954e1a-dc09-4811-b57d-b12bf69a767d/ - () https://wpscan.com/vulnerability/94954e1a-dc09-4811-b57d-b12bf69a767d/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:ablyperu:svg_uploads_support:*:*:*:*:*:wordpress:*:*

17 May 2025, 03:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento SVG Uploads Support de WordPress hasta la versión 2.1.1 no depura los archivos SVG cargados, lo que podría permitir que los usuarios con un rol tan bajo como Autor carguen un SVG malicioso que contenga payloads XSS.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-12 14:06


NVD link : CVE-2023-7086

Mitre link : CVE-2023-7086

CVE.ORG link : CVE-2023-7086


JSON object : View

Products Affected

ablyperu

  • svg_uploads_support
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')