Insecure SVG File Upload in SVG Support Plugin for WordPress
CVE-2022-4022
6.4MEDIUM
What is CVE-2022-4022?
The SVG Support plugin for WordPress versions 2.5 and 2.5.1 has a significant security flaw due to default insecure settings. This vulnerability allows authenticated users with author-level privileges to upload SVG files that may contain harmful JavaScript. Although the plugin introduced a sanitization feature for images during upload in version 2.5, it is disabled by default, leaving the system open to exploitation. Furthermore, there are no restrictions on SVG uploads, enabling potential attackers to insert malicious content that can be triggered when users visit the URL of the affected image.
Affected Version(s)
SVG Support 2.5
SVG Support 2.5.1