← back
CVE-2024-4271medium

SVGator <= 1.2.6 - Stored XSS via SVG Upload

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.6epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected products
Unknown · SVGator