ZeroHour

CVE-2024-11184

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p35
Published
()
Modified
Description

The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts

Vendors
wp enable svg project
Products
wp enable svg
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.