CVE-2026-13340
EUVD-2026-5217003.08.2026, 07:16
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.
Awaiting analysis
This vulnerability is currently awaiting analysis.