Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2023-4460
HistoryDec 04, 2023 - 9:28 p.m.

CVE-2023-4460 Uploading SVG, WEBP and ICO files <= 1.2.1 - Author+ Stored XSS via SVG

2023-12-0421:28:50
WPScan
github.com

AI Score

6

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

AI Score

6

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-4460