CVE-2024-8378
EUVD-2024-4913407.11.2024, 16:15
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| 10up | safe_svg | 𝑥 < 2.2.6 |
| 10up | safe_svg | 𝑥 < 2.2.6 |
𝑥
= Vulnerable software versions