CVE-2024-11184

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/01/2025
Last modified:
24/06/2025

Description

The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wp_enable_svg_project:wp_enable_svg:*:*:*:*:*:wordpress:*:* 0.7 (including)