← back
CVE-2024-4272medium

Support SVG < 1.1.0 - Stored XSS via SVG Upload

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.1epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Support SVG