Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50640 | The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads. |
Mon, 09 Jun 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goodlayers
Goodlayers goodlayers Core |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:goodlayers:goodlayers_core:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Goodlayers
Goodlayers goodlayers Core |
Thu, 30 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 30 Jan 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads. | |
| Title | GoodLayers Core < 2.1.3 - Subscriber+ Stored XSS via SVG Upload | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-30T15:56:20.975Z
Reserved: 2024-12-04T14:39:50.959Z
Link: CVE-2024-12163
Updated: 2025-01-30T15:56:11.488Z
Status : Analyzed
Published: 2025-01-30T06:15:29.113
Modified: 2025-06-09T21:19:40.777
Link: CVE-2024-12163
No data.
OpenCVE Enrichment
No data.
EUVD