PLUGIN SECURITY

Is Svg Vector Icon Plugin safe?

Securely upload SVG files to your media library, with built-in sanitization and advanced features for styling and animation.

What this plugin does

  • Slug: svg-vector-icon-plugin
  • Author: Benbodhi
  • 1000000+ active installs
  • 96/100 rating (356 reviews on wordpress.org)
  • 14999358 all-time downloads
  • On WordPress.org since 2014-07-22

mime typesafe svgsanitizationSVGVector

Maintenance status

  • Latest known version: 2.6.1
  • Last updated: 2026-07-25 11:26pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

2 known CVEs on file for Svg Vector Icon Plugin. Reported between 2019 and 2022.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0863 WP SVG Icons [svg-vector-icon-plugin] <= 3.2.3 (unfixed + closed) Unrestricted Upload of File with Dangerous Type High 7.2 < 3.2.3 3.2.3 2022-05-18 ⚠ update needed
CVE-2019-14216 WP SVG Icons [svg-vector-icon-plugin] < 3.2.3 (closed) Cross-Site Request Forgery (CSRF) High 8.8 < 3.2.3 3.2.3 2019-08-09 ⚠ update needed

How to fix it

Keep Svg Vector Icon Plugin updated — 2.6.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.