CVE-2023-4460
04.12.2023, 22:15
The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
Vendor | Product | Version |
---|---|---|
uploading_svg\,_webp_and_ico_files_project | uploading_svg\,_webp_and_ico_files | 𝑥 ≤ 1.2.1 |
𝑥
= Vulnerable software versions