Medium severity6.1NVD Advisory· Published May 15, 2025· Updated Jun 17, 2026
CVE-2023-6541
CVE-2023-6541
Description
The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/bbe866b8-7497-4e5c-8f59-bb8edac1dc71/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.