CVE-2023-5458 Information

Description

The CITS Support svg webp Media and TTFOTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

Reference

https://wpscan.com/vulnerability/47d15f1c-b9ca-494d-be8f-63c30e92f9b8

Share on: