The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
Metrics
Affected Vendors & Products
References
History
Thu, 15 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sayedulsayem
Sayedulsayem support Svg |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:sayedulsayem:support_svg:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Sayedulsayem
Sayedulsayem support Svg |
Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-13T06:00:06.185Z
Updated: 2024-08-01T20:33:53.006Z
Reserved: 2024-04-26T19:30:40.100Z
Link: CVE-2024-4272
Updated: 2024-08-01T20:33:53.006Z
Status : Analyzed
Published: 2024-07-13T06:15:03.230
Modified: 2025-05-15T18:29:15.627
Link: CVE-2024-4272
No data.