Vulnerabilities (CVE)

Filtered by vendor Enable Svg Uploads Project Subscribe
Filtered by product Enable Svg Uploads
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2529 1 Enable Svg Uploads Project 1 Enable Svg Uploads 2024-02-28 N/A 5.4 MEDIUM
The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.