Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j77f-79w9-rghc | The wp-enable-svg WordPress plugin does not sanitize SVG files when uploaded |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 24 Jun 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wp Enable Svg Project
Wp Enable Svg Project wp Enable Svg |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:wp_enable_svg_project:wp_enable_svg:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wp Enable Svg Project
Wp Enable Svg Project wp Enable Svg |
Mon, 06 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 02 Jan 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts | |
| Title | WP Enabled SVG <= 0.7 - Author+ Stored XSS via SVG | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-06T20:30:08.869Z
Reserved: 2024-11-13T15:55:57.036Z
Link: CVE-2024-11184
Updated: 2025-01-06T20:30:02.676Z
Status : Analyzed
Published: 2025-01-02T06:15:06.697
Modified: 2025-06-24T00:21:37.557
Link: CVE-2024-11184
No data.
OpenCVE Enrichment
No data.
Github GHSA