nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-36343 CVE-2022-36343
LOW
WordPress Enable SVG, WebP & ICO Upload plugin <= 1.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Record summary
CVE-2022-36343 has a selected CVSS score of 3.4 (low).
Description
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Enable SVG, WebP & ICO Upload (WordPress plugin)Browse ideasToCode / Enable SVG, WebP & ICO Upload (WordPress plugin) | CVE List | <= 1.0.1 to ≤ 1.0.1 | affected |
References
3patchstack.comConfirmation
https://patchstack.com/database/vulnerability/enable-svg-webp-ico-upload/wordpress-enable-svg-webp-ico-upload-plugin-1-0-1-authenticated-stored-cross-site-scripting-xss-vulnerability wordpress.orgConfirmation
https://wordpress.org/plugins/enable-svg-webp-ico-upload