CVE-2024-10222
The SVG Support plugin for WordPress before version 2.5.11 contains a stored cross-site scripting vulnerability that can be exploited through SVG file uploads. Authenticated users with Author privileges or higher can inject malicious scripts into SVG files due to inadequate sanitization and escaping, allowing the scripts to execute when other users view the affected files. While administrators have this capability by default, the vulnerability becomes more exploitable if SVG upload permissions are granted to lower-privileged user roles like authors.
Based on public CVE data (MITRE/NVD).