plugin

Cits Support Svg Webp Media Upload Vulnerabilities

3 known security issues reported for the Cits Support Svg Webp Media Upload WordPress plugin. Most recent disclosed Mar 21, 2025.

3 medium

Running Cits Support Svg Webp Media Upload on your site? Check whether your installed version is affected.

Scan your site free

CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts <= 4.2 - Cross-Site Request Forgery to Settings Update

medium

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_settings_tab() function. This makes it possible for unauthenticated atta...

CVSS:
4.3
Affected:
up to 4.2
Fix:
No patched version reported
Disclosed:
Mar 21, 2025

CVE-2025-0807 on NVD →

CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts <= 4.2 - Cross-Site Request Forgery to Font Assignment Deletion

medium

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_assign_fonts_tab() function. This makes it possible for unauthenticated...

CVSS:
4.3
Affected:
up to 4.2
Fix:
No patched version reported
Disclosed:
Mar 21, 2025

CVE-2024-13768 on NVD →

CITS Support svg, webp Media and TTF,OTF File Upload <= 2.1.0 - Authenticated(Author+) Stored Cross-Site Scripting via SVG Upload

medium

The CITS Support svg, webp Media and TTF,OTF File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG upload in versions up to, and including, 2.1.0 due to insufficient SVG sanitization. This makes it possible for authenticated attackers with Author permissions or above to inject arbitrary...

CVSS:
6.4
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Oct 9, 2023

CVE-2023-5458 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database