The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
History

Thu, 15 May 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Sayedulsayem
Sayedulsayem support Svg
Weaknesses CWE-79
CPEs cpe:2.3:a:sayedulsayem:support_svg:*:*:*:*:*:wordpress:*:*
Vendors & Products Sayedulsayem
Sayedulsayem support Svg

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-13T06:00:06.185Z

Updated: 2024-08-01T20:33:53.006Z

Reserved: 2024-04-26T19:30:40.100Z

Link: CVE-2024-4272

cve-icon Vulnrichment

Updated: 2024-08-01T20:33:53.006Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-13T06:15:03.230

Modified: 2025-05-15T18:29:15.627

Link: CVE-2024-4272

cve-icon Redhat

No data.