CVE-2023-6541 Information
May 16, 2025
cve
Description
The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
Reference
https://wpscan.com/vulnerability/bbe866b8-7497-4e5c-8f59-bb8edac1dc71/
Share on: