The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
Metrics
Affected Vendors & Products
References
History
Thu, 15 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sayedulsayem
Sayedulsayem support Svg |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:sayedulsayem:support_svg:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Sayedulsayem
Sayedulsayem support Svg |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-13T06:00:06.185Z
Updated: 2024-08-01T20:33:53.006Z
Reserved: 2024-04-26T19:30:40.100Z
Link: CVE-2024-4272

Updated: 2024-08-01T20:33:53.006Z

Status : Analyzed
Published: 2024-07-13T06:15:03.230
Modified: 2025-05-15T18:29:15.627
Link: CVE-2024-4272

No data.