Medium severity4.8NVD Advisory· Published Jan 2, 2025· Updated Jun 17, 2026
CVE-2024-11184
CVE-2024-11184
Description
The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mwdelaney/wp-enable-svgPackagist | <= 0.2 | — |
Affected products
3- cpe:2.3:a:wp_enable_svg_project:wp_enable_svg:*:*:*:*:*:wordpress:*:*Range: <=0.7
Patches
Vulnerability mechanics
References
4- wpscan.com/vulnerability/fc982bcb-9974-481f-aef4-580ae9edc3c8/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-j77f-79w9-rghcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-11184ghsaADVISORY
- wpscan.com/vulnerability/fc982bcb-9974-481f-aef4-580ae9edc3c8ghsaWEB
News mentions
0No linked articles in our index yet.