CVE · Medium

CVE-2022-1091 — Safe SVG [safe-svg] < 1.9.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1091 Safe SVG [safe-svg] < 1.9.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.9.10 1.9.10 2022-03-25

CVE-2022-1091

The Safe SVG plugin versions before 1.9.10 contain a sanitization bypass vulnerability that allows attackers to manipulate the content-type header during file uploads, circumventing the plugin's security checks. By exploiting this flaw, an attacker can upload malicious SVG files that execute cross-site scripting attacks or potentially conduct other XML-based attacks depending on how the uploaded files are subsequently processed. The vulnerability undermines the core protective functionality that the plugin is designed to provide.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.