CVE-2024-9238

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:grandplugins:avif_uploader:*:*:*:*:*:wordpress:*:*

History

12 Jun 2025, 16:31

Type Values Removed Values Added
CWE CWE-79
References () https://wpscan.com/vulnerability/a7de0cf6-3064-4595-9037-f8407fe40724/ - () https://wpscan.com/vulnerability/a7de0cf6-3064-4595-9037-f8407fe40724/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:grandplugins:avif_uploader:*:*:*:*:*:wordpress:*:*
First Time Grandplugins avif Uploader
Grandplugins

17 May 2025, 04:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

16 May 2025, 14:42

Type Values Removed Values Added
Summary
  • (es) El complemento AVIF Uploader de WordPress anterior a la versión 1.1.1 no depura los archivos SVG cargados, lo que podría permitir que los usuarios con un rol tan bajo como Autor carguen un SVG malicioso que contenga payloads XSS.

15 May 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:16

Updated : 2025-06-12 16:31


NVD link : CVE-2024-9238

Mitre link : CVE-2024-9238

CVE.ORG link : CVE-2024-9238


JSON object : View

Products Affected

grandplugins

  • avif_uploader
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')