Input validation vulnerability in Zita Elementor Site Library 1.6.3

The plugin called Zita Elementor Site Library for WordPress has a security issue that allows attackers to insert harmful code through SVG file uploads. This can happen in all versions up to 1.6.3 because the plugin does not properly clean the input and output. This means that someone with Author-level access or higher can add code to a page that will run whenever someone opens the SVG file.

Detected in:

Zita Elementor Site Library fixed vulnerable versions: >= * <= 1.6.3
Zita Site Library for Elementor fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.