CVE-2024-11091
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
<p>The SVG Support plugin enables SVG (Scalable Vector Graphics) support in WordPress. This lightweight plugin allows you to upload and use SVG files in your WordPress media library without any restrictions.</p>
<p>This plugin is designed to be minimalistic and focuses solely on enabling SVG support. It does not enqueue any additional scripts or stylesheets in the frontend, ensuring it won’t affect the loading speed of your website.</p>
<p>See plugin’s GitHub repo <a href="https://github.com/sayedulsayem/support-svg" rel="nofollow ugc">Support SVG</a></p>
<h3><strong>Features</strong></h3>
<ul>
<li>Enables SVG uploads in WordPress media library</li>
<li>Supports SVG thumbnail display in the Media Library</li>
<li>Applies necessary security measures to sanitize SVG uploads</li>
<li>Lightweight and does not enqueue any frontend scripts or stylesheets</li>
</ul>
<h3><strong>PRIVACY POLICY</strong></h3>
<p>This plugin does not collect, log, sell or trade any kind of information about your website. You can easily verify that this plugin is not phoning home using a network traffic inspector like <a href="https://www.wireshark.org/" rel="nofollow ugc">WireShark</a>.</p>
<h3><strong>ABOUT THE MAKER</strong></h3>
<p>I am <a href="https://sayedulsayem.com/" rel="nofollow ugc">Sayedul Sayem</a>, a Bangladeshi full-stack WordPress developer and free and open source enthusiast. You can contact me at my <a href="https://www.linkedin.com/in/sayedulsayem/" rel="nofollow ugc">LinkedIn</a> for consultation or just to say hello. I love talking to new people. So don’t hesitate.</p>