Back

MEDIUM

SVGator <= 1.2.6 - Stored XSS via SVG Upload

Published Jun 14, 2024

Description

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jun 14, 2024
Updated Aug 1, 2024
Reserved Apr 26, 2024
CISA Vulnrichment
Updated Jun 14, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a