PT-2025-47285 · WordPress · Enable Svg

Michael Mazzolini

·

Published

2025-11-18

·

Updated

2025-11-18

·

CVE-2025-13069

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Enable SVG, WebP, and ICO Upload plugin for WordPress versions up to and including 1.1.2
Description The Enable SVG, WebP, and ICO Upload plugin for WordPress is susceptible to arbitrary file upload due to insufficient file type validation when handling ICO files. This allows attackers to bypass sanitization by using double extensions and appropriate magic bytes, potentially enabling the upload of malicious files. Successful exploitation could lead to remote code execution on the affected server. The issue affects authenticated attackers with author-level access or higher.
Recommendations Update the Enable SVG, WebP, and ICO Upload plugin to a version later than 1.1.2.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-13069

Affected Products

Enable Svg