CVE-2022-4022
The SVG Support plugin versions 2.5 and 2.5.1 leave sanitization disabled by default, failing to remove malicious JavaScript embedded in SVG files. Any authenticated user with author-level access or above can upload dangerous SVG files to the site, and when these files are embedded in posts or pages, the malicious code executes in visitors' browsers. The vulnerability also triggers when users directly visit the SVG image URL, enabling arbitrary code execution. This issue was fixed in version 2.5.2.
Based on public CVE data (MITRE/NVD).