WP Clinic
Log in Sign up

CVE · Medium

CVE-2022-23638 — SVG Support [svg-support] < 2.5.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-23638 SVG Support [svg-support] < 2.5.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.5.9 2.5.9 2022-02-14

CVE-2022-23638

The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, and including, 2.5.8. The vulnerable dependency has a Stored Cross-Site Scripting vulnerability due to insufficient SVG sanitization. The SVG Support plugin may be exploited if the uploaded SVG image is included in line in an HTML page.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.