Safe SVG
Safe SVG has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2024; all 6 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 7.7 out of 10. Severity breakdown: 0 critical and 2 high. 2019 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 4 of the records (67%). Other recurring categories include Uncontrolled Resource Consumption.
Every one of the 6 issues recorded for Safe SVG has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, most of them (2) reported by Nguyen Thanh Nguyen. Safe SVG is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-1091Safe SVG <= 1.9.9 - Content-Type Bypass
Read the full analysisVulnerability Records

Safe SVG
Author
10up
Safe SVG is the best way to Allow SVG Uploads in WordPress! It gives you the ability to allow SVG uploads whilst making sure that they’re sanitized to stop SVG/XML vulnerabilities affecting your site. It also gives you the ability to preview your uploaded SVGs in the media library in all views. Current Features Sanitised SVGs – Don’t open up security holes in your WordPress site by allowing uploads of unsanitised files. SVGO Optimisation – Runs your SVGs through the SVGO tool on upload to save you space. This feature is disabled by default but can be enabled by adding the following code: add_filter( 'safe_svg_optimizer_enabled', '__return_true' ); View SVGs in the Media Library – Gone are the days of guessing which SVG is the correct one, we’ll enable SVG previews in the WordPress media library. Choose Who Can Upload – Restrict SVG uploads to certain users on your WordPress site or allow anyone to upload. Initially a proof of concept for #24251. SVG Sanitization is done through the following library: https://github.com/darylldoyle/svg-sanitizer. SVG Optimization is done through the following library: https://github.com/svg/svgo. Technical: Upload Path Security WordPress’s _wp_handle_upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action}_prefilter. Safe SVG hooks common actions like wp_handle_upload and wp_handle_sideload, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C