What the vulnerability does
01Description
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The Enable SVG, WebP & ICO Upload plugin for WordPress versions up to 1.0.1 contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts through the plugin's upload or settings functionality. When other users view the affected content, the injected script executes in their browser, potentially compromising their session or stealing sensitive data.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view the affected page.
Potential impact on your site
A compromised admin account can inject persistent malicious scripts affecting all site visitors, risking session hijacking or credential theft.
Conditions required to exploit
Attacker must be logged in as an administrator. A user must visit the page containing the injected content.
Key dates
External resources
Related vulnerabilities