Input validation vulnerability in Enable SVG Uploads 2.1.5

The Enable SVG Uploads plugin for WordPress is not secure in versions up to and including 2.1.5. It does not properly filter and protect input and output, which allows attackers with an author-level or higher permission to inject malicious web scripts into pages. If a user visits one of these injected pages, the malicious code will execute.

Detected in:

Enable SVG Uploads open vulnerable versions: >= * <= 2.1.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.