MidnightBSD

Advisories for sayedulsayem

CVE-2024-4272

The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

Products Affected

Vendor Product Version
sayedulsayem support_svg *