WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Svg Support safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Svg Support WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: svg-support

Maintenance status

Known vulnerabilities

7 known CVEs on file for Svg Support. Reported between 2022 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-48973 SVG Support [svg-support] < 2.5.15 Missing Authorization Medium 4.3 < 2.5.15 2.5.15 2026-05-27
CVE-2024-10222 SVG Support [svg-support] < 2.5.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.5.11 2.5.11 2025-02-21
CVE-2023-6708 SVG Support [svg-support] < 2.5.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.5.8 2.5.8 2024-07-17
CVE-2022-4022 SVG Support [svg-support] < 2.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.5.2 2.5.2 2022-11-16
CVE-2022-1755 SVG Support [svg-support] < 2.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.5 2.5 2022-09-05
CVE-2022-23638 SVG Support [svg-support] < 2.5.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.5.9 2.5.9 2022-02-14
CVE-2021-24686 SVG Support [svg-support] < 2.3.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.3.20 2.3.20 2022-01-03

CVE-2026-48973

The SVG Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.14. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

Source: Wordfence

CVE-2024-10222

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to upload SVG files can be extended to authors.

Source: CVE.org

CVE-2023-6708

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that successful exploitation of this vulnerability requires the administrator to allow author-level users to upload SVG files. As of 2.5.6, SVG sanitization can still be bypassed by supplying a content-type other than image/svg+xml.

Source: Wordfence

CVE-2022-4022

The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are uploaded, the plugin defaults to disable sanitization and does not restrict SVG upload to only administrators. This allows authenticated attackers, with author-level privileges and higher, to upload malicious SVG files that can be embedded in posts and pages by higher privileged users. Additionally, the embedded JavaScript is also triggered on visiting the image URL, which allows an attacker to execute malicious code in browsers visiting that URL.

Source: CVE.org

CVE-2022-1755

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parameter in versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2022-23638

The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, and including, 2.5.8. The vulnerable dependency has a Stored Cross-Site Scripting vulnerability due to insufficient SVG sanitization. The SVG Support plugin may be exploited if the uploaded SVG image is included in line in an HTML page.

Source: Wordfence

CVE-2021-24686

The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Source: CVE.org

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.