Known vulnerabilities, PHP compatibility and safer alternatives for the Svg Support WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
Maintenance status
Known vulnerabilities
7 known CVEs on file for Svg Support.
Reported between 2022 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-48973
|
SVG Support [svg-support] < 2.5.15 |
Missing Authorization |
Medium
4.3
|
< 2.5.15
|
2.5.15 |
2026-05-27 |
—
|
|
CVE-2024-10222
|
SVG Support [svg-support] < 2.5.11 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 2.5.11
|
2.5.11 |
2025-02-21 |
—
|
|
CVE-2023-6708
|
SVG Support [svg-support] < 2.5.8 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.5.8
|
2.5.8 |
2024-07-17 |
—
|
|
CVE-2022-4022
|
SVG Support [svg-support] < 2.5.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.5.2
|
2.5.2 |
2022-11-16 |
—
|
|
CVE-2022-1755
|
SVG Support [svg-support] < 2.5 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.5
|
2.5 |
2022-09-05 |
—
|
|
CVE-2022-23638
|
SVG Support [svg-support] < 2.5.9 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.5.9
|
2.5.9 |
2022-02-14 |
—
|
|
CVE-2021-24686
|
SVG Support [svg-support] < 2.3.20 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 2.3.20
|
2.3.20 |
2022-01-03 |
—
|
CVE-2026-48973
The SVG Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.14. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
Source:
Wordfence
CVE-2024-10222
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to upload SVG files can be extended to authors.
Source:
CVE.org
CVE-2023-6708
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that successful exploitation of this vulnerability requires the administrator to allow author-level users to upload SVG files. As of 2.5.6, SVG sanitization can still be bypassed by supplying a content-type other than image/svg+xml.
Source:
Wordfence
CVE-2022-4022
The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are uploaded, the plugin defaults to disable sanitization and does not restrict SVG upload to only administrators. This allows authenticated attackers, with author-level privileges and higher, to upload malicious SVG files that can be embedded in posts and pages by higher privileged users. Additionally, the embedded JavaScript is also triggered on visiting the image URL, which allows an attacker to execute malicious code in browsers visiting that URL.
Source:
CVE.org
CVE-2022-1755
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parameter in versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2022-23638
The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, and including, 2.5.8. The vulnerable dependency has a Stored Cross-Site Scripting vulnerability due to insufficient SVG sanitization. The SVG Support plugin may be exploited if the uploaded SVG image is included in line in an HTML page.
Source:
Wordfence
CVE-2021-24686
The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Source:
CVE.org
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.