Conversation
supportEnable SVG, WebP & ICO Upload plugin <= 1.0.3 – Authenticated Arbitrary File Upload Enable SVG, WebP & ICO Upload plugin <= 1.0.3 – Authenticated Stored Cross-Site Scripting (XSS) vulnerability https://patchstack.com/database/vulnerability/enable-svg-webp-ico-upload/wordpress-enable-svg-webp-ico-upload-plugin-1-0-1-authenticated-arbitrary-file-upload-vulnerability?_a_id=110 https://patchstack.com/database/vulnerability/enable-svg-webp-ico-upload/wordpress-enable-svg-webp-ico-upload-plugin-1-0-1-authenticated-stored-cross-site-scripting-xss-vulnerability?_a_id=110 This topic was modified 3 years ago by spiralofhope . Reason: clarity This topic was modified 3 years ago by spiralofhope .
Indeed, WP Scan also detects the same vulnerability: https://wpscan.com/vulnerability/91898762-aa7d-4fbc-a016-3de48901e5de And Wordfence as well, of course: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/enable-svg-webp-ico-upload/enable-svg-webp-ico-upload-103-authenticated-author-stored-cross-site-scripting-via-svg At the time of writing, a full disclosure about the vulnerability was not yet publicly shown on the assigned vulnerability numbered CVE-2023-2143 , but it will be soon. Allegedly, the author of this plugin was contacted back in April 2023 to fix the vulnerability. These days, all SVGs ought to be properly sanitized before allowing them to be user-uploaded (as the SafeSVG plugin already does), not merely ‘enabling’ the Media Library to upload SVG files… This reply was modified 3 years ago by Gwyneth Llewelyn . Reason: Added a few more tags
Indeed, WP Scan also detects the same vulnerability: https://wpscan.com/vulnerability/91898762-aa7d-4fbc-a016-3de48901e5de And Wordfence as well, of course: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/enable-svg-webp-ico-upload/enable-svg-webp-ico-upload-103-authenticated-author-stored-cross-site-scripting-via-svg At the time of writing, a full disclosure about the vulnerability was not yet publicly shown on the assigned vulnerability numbered CVE-2023-2143 , but it will be soon. Allegedly, the author of this plugin was contacted back in April 2023 to fix the vulnerability. These days, all SVGs ought to be properly sanitized before allowing them to be user-uploaded (as the SafeSVG plugin already does), not merely ‘enabling’ the Media Library to upload SVG files… This reply was modified 3 years ago by Gwyneth Llewelyn . Reason: Added a few more tags