VulnerabilityModified
CVE-2022-1939
The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to
HIGH 7.2EPSS 1.45%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- allow svg files project/allow svg files
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/4d7b62e1-558b-4504-a6e2-78246a8b554fExploit, Third Party Advisory
- https://wpscan.com/vulnerability/4d7b62e1-558b-4504-a6e2-78246a8b554fExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.