PT-2025-12856 · WordPress · Wp-Svg-Upload

Pierre Rudloff

·

Published

2025-03-26

·

Updated

2025-03-26

·

CVE-2024-11847

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions wp-svg-upload WordPress plugin version 1.0.0
Description The issue concerns the wp-svg-upload WordPress plugin, which does not sanitize SVG file contents. This enables users with at least the author role to upload SVG files with malicious JavaScript, allowing them to conduct Stored XSS attacks.
Recommendations For version 1.0.0, consider disabling the ability to upload SVG files until a patch is available to prevent Stored XSS attacks. Restrict access to the plugin's functionality for users with the author role and below to minimize the risk of exploitation. Avoid using the plugin to upload SVG files with JavaScript content until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11847
GHSA-V2RR-FHV8-MX74

Affected Products

Wp-Svg-Upload