CVE-2022-1091
The Safe SVG plugin versions before 1.9.10 contain a sanitization bypass vulnerability that allows attackers to manipulate the content-type header during file uploads, circumventing the plugin's security checks. By exploiting this flaw, an attacker can upload malicious SVG files that execute cross-site scripting attacks or potentially conduct other XML-based attacks depending on how the uploaded files are subsequently processed. The vulnerability undermines the core protective functionality that the plugin is designed to provide.
Based on public CVE data (MITRE/NVD).