CVE-2026-48973 MEDIUM

CVE-2026-48973: WordPress SVG Support plugin <= 2.5.14 - Broken Access Control vulnerability

Vendor Benbodhi
Product SVG Support
Weakness CWE-862 · Missing authorization
Published May 27, 2026
Last update May 27, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14.

Explanation of Vulnerability in Simple Terms

02Summary

SVG Support versions up to 2.5.14 lack proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with low-level account privileges can alter data through SVG processing without proper permission validation. The vulnerability affects the integrity of site content but does not expose sensitive information or cause service disruption.

What an attacker can do

03Attacker Capabilities

Modify content or settings they lack permission to change.

Potential impact on your site

04Site Impact

Authenticated users can alter site content or configuration beyond their assigned permissions.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account on the site; no user interaction required.

Key dates

06Disclosure timeline

May 27, 2026 CVE published
May 27, 2026 Record updated

Related vulnerabilities

08Related CVE