CVE Database /
CVE-2019-14216
CVE · High
CVE-2019-14216 — WP SVG Icons [svg-vector-icon-plugin] < 3.2.3 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-14216
|
WP SVG Icons [svg-vector-icon-plugin] < 3.2.3 (closed) |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 3.2.3
|
3.2.3 |
2019-08-09 |
—
|
CVE-2019-14216
The WP SVG Icons plugin before version 3.2.3 contains a cross-site request forgery vulnerability in its custom icon upload functionality. An attacker could exploit this weakness to trick an authenticated administrator into uploading a malicious ZIP file containing a PHP script through the plugin's custom icon settings page. This flaw allows arbitrary file upload that could lead to remote code execution on the affected WordPress installation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings