CVE · High

CVE-2022-0863 — WP SVG Icons [svg-vector-icon-plugin] <= 3.2.3 (unfixed + closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0863 WP SVG Icons [svg-vector-icon-plugin] <= 3.2.3 (unfixed + closed) Unrestricted Upload of File with Dangerous Type High 7.2 < 3.2.3 3.2.3 2022-05-18

CVE-2022-0863

The WP SVG Icons plugin up to version 3.2.3 contains an authenticated remote code execution vulnerability that allows logged-in users to execute arbitrary code on affected WordPress installations. The plugin was closed and removed from availability on April 18, 2022 due to this security flaw, with no patched version released. Users should immediately deactivate and remove the plugin from their systems as the issue remains unfixed.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.