Input validation vulnerability in Smart Icons For WordPress 1.0.4

The Smart Icons For WordPress plugin is at risk for a security issue called Stored Cross-Site Scripting. This can happen when someone uploads an SVG file. The plugin’s code doesn’t properly clean or protect the input, which means that someone with certain permissions can add their own code to the page. This could potentially cause harm to anyone who views the SVG file.

Detected in:

Smart Icons For WordPress open vulnerable versions: >= * <= 1.0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.