The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Safe_svg | 10up | * | 2.2.6 (excluding) |