Unrated severityNVD Advisory· Published Jun 27, 2022· Updated Aug 3, 2024
Easy SVG Support < 3.3.0 - Author+ Stored Cross Site Scripting via SVG
CVE-2022-1964
Description
The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
Affected products
1- Range: <3.3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/52cf7e3c-2a0c-45c4-be27-be87424f1338mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.