Enable SVG, WebP, and ICO Upload
Enable SVG, WebP, and ICO Upload has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 5 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (60%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.
Every one of the 5 issues recorded for Enable SVG, WebP, and ICO Upload has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by Kim Jong Min. Enable SVG, WebP, and ICO Upload is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-13069Enable SVG, WebP, and ICO Upload <= 1.1.3 - Authenticated (Author+) Arbitrary File Upload via ICO Upload Bypass
Read the full analysisVulnerability Records

Enable SVG, WebP, and ICO Upload
Author
ideasToCode
By default, WordPress does not allow uploading file formats like SVG, WebP, and ICO (in some hostings) citing security reasons. These files are becoming very popular and in fact, are recommended by popular web speed scan platforms like Google PageSpeed Insights or Gtmetrix to resolve the serve images in nextgen formats. Thus, this FREE PLUGIN will enable you to upload these files. Simply install the plugin and your WordPress website now can easily accept media in SVG, WebP, and ICO format. You will also have an option to disable some or all images format (of the three) as required. Tutorial video If you want to learn more about the plugin – please check our website – ideastocode.com.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C