WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Svg Support?

Securely upload SVG files to your media library, with built-in sanitization and advanced features for styling and animation.

Qué hace este plugin

  • Slug: svg-support
  • Autor: Benbodhi
  • 1000000+ instalaciones activas
  • 96/100 calificación (355 reseñas en wordpress.org)
  • 14319065 descargas totales
  • En WordPress.org desde 2014-07-22

mime typesafe svgsanitizationSVGVector

Estado de mantenimiento

  • Última actualización: 2026-07-25 11:26pm GMT
  • Probado hasta WordPress: 7.0.2
  • Requiere PHP: 7.4+

Vulnerabilidades conocidas

7 CVEs conocidos registrados para Svg Support. Reportadas entre 2022 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-48973 SVG Support [svg-support] < 2.5.15 Falta de control de autorización Media 4,3 < 2.5.15 2.5.15 2026-05-27
CVE-2024-10222 SVG Support [svg-support] < 2.5.11 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 2.5.11 2.5.11 2025-02-21
CVE-2023-6708 SVG Support [svg-support] < 2.5.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.5.8 2.5.8 2024-07-17
CVE-2022-4022 SVG Support [svg-support] < 2.5.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.5.2 2.5.2 2022-11-16
CVE-2022-1755 SVG Support [svg-support] < 2.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.5 2.5 2022-09-05
CVE-2022-23638 SVG Support [svg-support] < 2.5.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 2.5.9 2.5.9 2022-02-14
CVE-2021-24686 SVG Support [svg-support] < 2.3.20 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 2.3.20 2.3.20 2022-01-03

CVE-2026-48973

The SVG Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.14. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-10222

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to upload SVG files can be extended to authors.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-6708

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that successful exploitation of this vulnerability requires the administrator to allow author-level users to upload SVG files. As of 2.5.6, SVG sanitization can still be bypassed by supplying a content-type other than image/svg+xml.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-4022

The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are uploaded, the plugin defaults to disable sanitization and does not restrict SVG upload to only administrators. This allows authenticated attackers, with author-level privileges and higher, to upload malicious SVG files that can be embedded in posts and pages by higher privileged users. Additionally, the embedded JavaScript is also triggered on visiting the image URL, which allows an attacker to execute malicious code in browsers visiting that URL.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-1755

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parameter in versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-23638

The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, and including, 2.5.8. The vulnerable dependency has a Stored Cross-Site Scripting vulnerability due to insufficient SVG sanitization. The SVG Support plugin may be exploited if the uploaded SVG image is included in line in an HTML page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24686

The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.