Lucene search

K
patchstackLuan PedersiniPATCHSTACK:CC01B47DFAD304F70EEC45B916AFC06C
HistoryMay 03, 2022 - 12:00 a.m.

WordPress Enable SVG plugin <= 1.3.1 - Stored Cross-Site Scripting (XSS) vulnerability via SVG

2022-05-0300:00:00
Luan Pedersini
patchstack.com
12
wordpress enable svg
stored xss
svg
luan pedersini
update
version 1.4.0

EPSS

0.001

Percentile

24.8%

Stored Cross-Site Scripting (XSS) vulnerability via SVG discovered by Luan Pedersini in WordPress Enable SVG plugin (versions <= 1.3.1).

Solution

           Update the WordPress Enable SVG plugin to the latest available version (at least 1.4.0).

EPSS

0.001

Percentile

24.8%

Related for PATCHSTACK:CC01B47DFAD304F70EEC45B916AFC06C