NA

CVE-2023-5458

Published: 31/10/2023 Updated: 08/11/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin prior to 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

Vulnerable Product Search on Vulmon Subscribe to Product

ashik cits support svg\\, webp media and ttf\\,otf file upload