SVG Support, CVE-2026-13340
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 03, 2026
- Research Description
- The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.
- Affected versions
-
max 2.5.17.
- Status
-
vulnerable