Easy SVG Support, CVE-2022-1964
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jun 27, 2022
- Research Description
- The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
- Affected versions
-
max 3.3.0.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Easy SVG Support (CVE-2024-10269) , Nov 08, 2024 |
| Easy SVG Support (CVE-2022-1964) , Jun 07, 2024 |
| Easy SVG Support (CVE-2025-12451) , Feb 27, 2026 |