SECURITY FIX – SVG XSS VULNERABILITY
– Fixed: Stored Cross-Site Scripting (XSS) vulnerability via SVG file uploads reported by Wordfence
– Security: Implemented whitelist-based SVG sanitization using the enshrined/svg-sanitize library
– Security: Extended fallback blacklist to include SVG animation events (onbegin, onend, onrepeat, onactivate)
– Security: Added comprehensive coverage for all known SVG XSS vectors including SMIL animation events
– Security: Added protection against javascript:, data:, and vbscript: URL schemes in SVG attributes
– Security: Added validation to prevent malicious animate/set elements targeting event handlers
Plugin Website
Visit website
Share Post
Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.