CVE-2023-7088

The Add SVG Support for Media Uploader | inventivo WordPress plugin through 1.0.5 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:inventivo:inventivo:*:*:*:*:*:wordpress:*:*

History

12 Jun 2025, 14:04

Type Values Removed Values Added
CWE CWE-79
References () https://wpscan.com/vulnerability/8f515e36-9072-4fc4-9d2f-d50f1adde626/ - () https://wpscan.com/vulnerability/8f515e36-9072-4fc4-9d2f-d50f1adde626/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:inventivo:inventivo:*:*:*:*:*:wordpress:*:*
First Time Inventivo inventivo
Inventivo

17 May 2025, 03:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento Add SVG Support for Media Uploader | inventivo WordPress hasta la versión 1.0.5 no depura los archivos SVG cargados, lo que podría permitir que los usuarios con un rol tan bajo como Autor carguen un SVG malicioso que contenga payloads XSS.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-12 14:04


NVD link : CVE-2023-7088

Mitre link : CVE-2023-7088

CVE.ORG link : CVE-2023-7088


JSON object : View

Products Affected

inventivo

  • inventivo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')