CVE-2024-11847
26.03.2025, 06:15
The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
| Vendor | Product | Version |
|---|---|---|
| wp_svg_upload_project | _wp_svg_upload | 𝑥 ≤ 1.0.0 |
𝑥
= Vulnerable software versions