CVE-2024-3633 Information

Description

The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

Reference

https://wpscan.com/vulnerability/2e0baffb-7ab8-4c17-aa2a-7f28a0be1a41/

Share on: