VYPR
Vendor

SVG Uploads Support

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2024-11091MedNov 26, 2024
    risk 0.35cvss 6.4epss 0.00

    The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2023-7086May 15, 2025
    risk 0.00cvss epss 0.00

    The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

  • CVE-2024-4272Jul 13, 2024
    risk 0.00cvss epss 0.00

    The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.