The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator. | |
| Title | SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-03T06:00:11.984Z
Reserved: 2026-06-25T14:09:15.204Z
Link: CVE-2026-13340
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T08:45:03Z