Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wp Svg Icons Project Subscribe
Filtered by product Wp Svg Icons
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0863 1 Wp Svg Icons Project 1 Wp Svg Icons 2023-01-19 6.5 MEDIUM 7.2 HIGH
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
CVE-2019-14216 1 Wp Svg Icons Project 1 Wp Svg Icons 2019-08-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file.