What is CVE-2026-13340?
CVE-2026-13340: The SVG Support WordPress plugin before 2.5.17 fails to apply its SVG sanitisation to files uploaded with the .svgz extension. This allows users with SVG upload permissions (e.g., Author role) to store script-bearing files. Updating to the latest plugin version is advised.
Azərbaycanca: CVE-2026-13340: SVG Support WordPress plaginin 2.5.17-dən əvvəlki versiyalarında .svgz uzantılı fayllar üçün sanitizasiya tətbiq olunmur. Bu zəiflik SVG yükləmə icazəsi olan istifadəçilərə (məsələn, Author rolu) script daşıyan sənəd yerləşdirməyə imkan verir. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the SVG Support plugin are affected by CVE-2026-13340?
This vulnerability affects versions of the SVG Support WordPress plugin before 2.5.17.
How can an attacker exploit CVE-2026-13340?
Users with SVG upload permissions (e.g., Author role) can bypass sanitisation by uploading files with the .svgz extension, allowing them to store script-bearing files on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.