The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross-Site Scripting vulnerability.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Enable_svg,webp&_ico_upload |
Ideastocode |
* |
1.0.3 (including) |
References