The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts
This Cyber News was published on www.tenable.com. Publication date: Fri, 03 Jan 2025 04:56:02 +0000