VYPR

Enable Svg Webp Ico Upload

by WordPress

Source repositories

CVEs (6)

  • CVE-2025-13069HigNov 18, 2025
    risk 0.57cvss 8.8epss 0.01

    The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This is due to insufficient file type validation detecting ICO files, allowing double extension files with the appropriate magic bytes to…

  • CVE-2025-12457MedNov 18, 2025
    risk 0.42cvss 6.4epss 0.00

    The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

  • CVE-2023-2143Jul 17, 2023
    risk 0.00cvss epss 0.00

    The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross-Site Scripting vulnerability.

  • CVE-2023-2529Jul 10, 2023
    risk 0.00cvss epss 0.01

    The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

  • CVE-2022-34154Aug 1, 2022
    risk 0.00cvss epss 0.01

    Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.

  • CVE-2022-36343Aug 1, 2022
    risk 0.00cvss epss 0.00

    Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.