CVE Vulnerabilities

CVE-2024-11184

Published: Jan 02, 2025 | Modified: Jun 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts

Affected Software

Name Vendor Start Version End Version
Wp_enable_svg Wp_enable_svg_project * 0.7 (including)

References