Uploading SVG, WEBP and ICO files <= 1.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
medium
The Uploading SVG, WEBP and ICO files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG images in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 1.2.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 13, 2023
CVE-2023-4460 on NVD →
Uploading SVG, WEBP and ICO files <= 1.0.1 - Arbitrary File Upload
high
The Uploading SVG, WEBP and ICO files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknown function in versions up to, and including, 1.0.1. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code ex...
- CVSS:
- 7.2
- Affected:
- up to 1.0.1
- Fixed in:
- 1.2.0
- Disclosed:
- Aug 12, 2022
CVE-2022-36285 on NVD →
Uploading SVG, WEBP and ICO files <= 1.0.1 - Authenticated Stored Cross-Site Scripting
medium
The Uploading SVG, WEBP and ICO files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 5.5
- Affected:
- up to 1.0.1
- Fixed in:
- 1.2.0
- Disclosed:
- Aug 12, 2022
CVE-2022-34648 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database