Vulnerabilities > Benbodhi > SVG Support > 2.4.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-21 | CVE-2024-10222 | Cross-site Scripting vulnerability in Benbodhi SVG Support The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. | 5.4 |
2022-09-26 | CVE-2022-1755 | Unspecified vulnerability in Benbodhi SVG Support The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks | 5.4 |