CVE · Medium

CVE-2022-4022 — SVG Support [svg-support] < 2.5.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4022 SVG Support [svg-support] < 2.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.5.2 2.5.2 2022-11-16

CVE-2022-4022

The SVG Support plugin versions 2.5 and 2.5.1 leave sanitization disabled by default, failing to remove malicious JavaScript embedded in SVG files. Any authenticated user with author-level access or above can upload dangerous SVG files to the site, and when these files are embedded in posts or pages, the malicious code executes in visitors' browsers. The vulnerability also triggers when users directly visit the SVG image URL, enabling arbitrary code execution. This issue was fixed in version 2.5.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.