The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-13340
Mitre link : CVE-2026-13340
CVE.ORG link : CVE-2026-13340
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
