CVE

CVE-2026-13340 — SVG Support [svg-support] < 2.5.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13340 SVG Support [svg-support] < 2.5.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 2.5.17 2.5.17 2026-07-24

CVE-2026-13340

The SVG Support WordPress plugin is vulnerable to a security flaw due to its failure to properly sanitize uploaded files with the .svgz extension. This oversight allows malicious users, even those with limited permissions like Authors granted upload access, to upload and store scripts that can be executed by anyone viewing the file, including administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.