The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
This Cyber News was published on www.tenable.com. Publication date: Fri, 22 Nov 2024 09:01:02 +0000