Report
The Allow SVG Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 1.1 due to insufficient sanitization and escaping on the SVG file. This makes it possible for authenticated attackers with file uploading capabilities, like an author, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Score:5.4
Severity:Medium
Version: 1.1
The plugin vendor has not patched this vulnerability at the moment.