CVE-2024-8378
07.11.2024, 16:15
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.Enginsight
Vendor | Product | Version |
---|---|---|
10up | safe_svg | 𝑥 < 2.2.6 |
10up | safe_svg | 𝑥 < 2.2.6 |
𝑥
= Vulnerable software versions