WP SVG Icons <= 3.2.3 - Authenticated (Admin+) Arbitrary File Upload
high
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing a high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
- CVSS:
- 7.2
- Affected:
- up to 3.2.3
- Fix:
- No patched version reported
- Disclosed:
- May 18, 2022
CVE-2022-0863 on NVD →
WP SVG Icons <= 3.2.2 - Cross-Site Request Forgery to Remote Code Execution
high
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.2 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file.
- CVSS:
- 8.8
- Affected:
- up to 3.2.3
- Fixed in:
- 3.2.3
- Disclosed:
- Aug 9, 2019
CVE-2019-14216 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database