Medium severity5.4NVD Advisory· Published Mar 18, 2024· Updated Jun 17, 2026
CVE-2023-7085
CVE-2023-7085
Description
The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:sterlinghamilton:scalable_vector_graphics_\(svg\):*:*:*:*:*:wordpress:*:*Range: <=3.4
- WordPress/Scalable Vector Graphics (SVG)description
- Range: <=3.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a2ec1308-75a0-49d0-9288-33c6d9ee4328/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.