Lucene search

K
wpvulndbDanilo AlbuquerqueWPVDB-ID:82F8D425-449A-471F-94DF-8439924FD628
HistoryNov 13, 2023 - 12:00 a.m.

Uploading SVG, WEBP and ICO files <= 1.2.1 - Author+ Stored XSS via SVG

2023-11-1300:00:00
Danilo Albuquerque
wpscan.com
9
plugin
svg
webp
ico
xss
author
vulnerability

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Description The plugin does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

PoC

As an author, upload an SVG file with malicious JavaScript: Access the file through its URL to see XSS.

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for WPVDB-ID:82F8D425-449A-471F-94DF-8439924FD628