cleantalk
Vulnerabilities and Security Researches

SVG Support, CVE-2022-1755

CVE, Research URL

CVE-2022-1755

Application

SVG Support

Published on
Sep 26, 2022
Research Description
The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks
Affected versions
Min -, max 2.5.
Status
vulnerable