CVE-2023-6708
The SVG Support plugin through version 2.5.7 fails to properly sanitize and escape SVG file uploads, allowing authenticated users with author-level permissions or higher to store malicious scripts that execute when pages containing the uploaded files are viewed. The vulnerability persists even when the built-in sanitization feature is active, and attackers can further bypass protections by uploading files with non-standard content types. This issue only affects sites where administrators have enabled SVG uploads for lower-privileged user accounts.
Based on public CVE data (MITRE/NVD).