Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-4460
HistoryDec 04, 2023 - 10:15 p.m.

Design/Logic Flaw

2023-12-0422:15:00
PRIOn knowledge base
www.prio-n.com
8
wordpress
plugin
xss
svg
webp
ico
security flaw

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for PRION:CVE-2023-4460