cleantalk
Vulnerabilities and Security Researches

Easy SVG Support, CVE-2022-1964

CVE, Research URL

CVE-2022-1964

Application

Easy SVG Support

Published on
Jun 27, 2022
Research Description
The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
Affected versions
max 3.3.0.
Status
vulnerable