CVE · High

CVE-2019-14216 — WP SVG Icons [svg-vector-icon-plugin] < 3.2.3 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-14216 WP SVG Icons [svg-vector-icon-plugin] < 3.2.3 (closed) Cross-Site Request Forgery (CSRF) High 8.8 < 3.2.3 3.2.3 2019-08-09

CVE-2019-14216

The WP SVG Icons plugin before version 3.2.3 contains a cross-site request forgery vulnerability in its custom icon upload functionality. An attacker could exploit this weakness to trick an authenticated administrator into uploading a malicious ZIP file containing a PHP script through the plugin's custom icon settings page. This flaw allows arbitrary file upload that could lead to remote code execution on the affected WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.