CVE · Medium

CVE-2023-6708 — SVG Support [svg-support] < 2.5.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6708 SVG Support [svg-support] < 2.5.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.5.8 2.5.8 2024-07-17

CVE-2023-6708

The SVG Support plugin through version 2.5.7 fails to properly sanitize and escape SVG file uploads, allowing authenticated users with author-level permissions or higher to store malicious scripts that execute when pages containing the uploaded files are viewed. The vulnerability persists even when the built-in sanitization feature is active, and attackers can further bypass protections by uploading files with non-standard content types. This issue only affects sites where administrators have enabled SVG uploads for lower-privileged user accounts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.