CVE · Medium

CVE-2024-10222 — SVG Support [svg-support] < 2.5.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10222 SVG Support [svg-support] < 2.5.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.5.11 2.5.11 2025-02-21

CVE-2024-10222

The SVG Support plugin for WordPress before version 2.5.11 contains a stored cross-site scripting vulnerability that can be exploited through SVG file uploads. Authenticated users with Author privileges or higher can inject malicious scripts into SVG files due to inadequate sanitization and escaping, allowing the scripts to execute when other users view the affected files. While administrators have this capability by default, the vulnerability becomes more exploitable if SVG upload permissions are granted to lower-privileged user roles like authors.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.