Extension WordPress
Vulnérabilités Enable SVG, WebP, and ICO Upload
Cette page rassemble les failles publiées pour Enable SVG, WebP, and ICO Upload, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Enable SVG, WebP, and ICO Upload
5 fiches
Enable SVG, WebP, and ICO Upload <= 1.1.3 – Authenticated (Author+) Arbitrary File Upload via ICO Upload Bypass
The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This is due to insufficient file type validation detecting ICO files, allowing double extension…
*-1.1.3
1.1.4
17/11/2025
Enable SVG, WebP, and ICO Upload <= 1.1.2 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploads
The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes…
*-1.1.2
1.1.3
17/11/2025
Enable SVG, WebP & ICO Upload <= 1.1.1 – Authenticated (Author+) Stored Cross-Site Scripting via SVG
The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient sanitization of SVG uploads. This makes it possible for authenticated attackers, with…
*-1.1.1
1.1.2
23/06/2023
Enable SVG, WebP & ICO Upload <= 1.1.0 – Arbitrary File Upload
The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 1.1.0. This makes it possible for authenticated attackers to upload…
*-1.1.0
1.1.1
01/08/2022
Enable SVG, WebP & ICO Upload <= 1.0.2 – Authenticated (Author+) Stored Cross-Site Scripting
The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.0.2
1.0.3
01/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.