CVE-2024-10269
Benjaminzekavica
CVE-2024-10269: Stored Cross-Site Scripting (XSS) vulnerability in the Easy SVG Support plugin for WordPress. This vulnerability allows authenticated attackers with Author-level access or higher to inject malicious web scripts into SVG files uploaded via the REST API. These scripts execute whenever a user accesses the compromised SVG, potentially leading to account compromise or other malicious activities.
Easy SVG Support plugin for WordPress versions 3.7 and earlier is vulnerable. With an SVRS of 53, while not critical, the associated risks remain significant. Successful exploitation could allow attackers to perform actions such as stealing sensitive information, redirecting users to malicious websites, or defacing the website. Although the CVSS score is 5.4, the SVRS highlights that while not critical, due to 'In The Wild' tag, patching should be done after critical vulnerabilities are addressed.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.