CVE-2022-0863
13.06.2022, 13:15
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
wp_svg_icons_project | wp_svg_icons | 𝑥 ≤ 3.2.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration