Support SVG – Upload svg files in wordpress without hassle
Support SVG – Upload svg files in wordpress without hassle has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Support SVG – Upload svg files in wordpress without hassle has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Support SVG – Upload svg files in wordpress without hassle is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-11091Support SVG – Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG File Upload
Read the full analysisVulnerability Records

Support SVG – Upload svg files in wordpress without hassle
Author
Sayedul Sayem
The SVG Support plugin enables SVG (Scalable Vector Graphics) support in WordPress. This lightweight plugin allows you to upload and use SVG files in your WordPress media library without any restrictions. This plugin is designed to be minimalistic and focuses solely on enabling SVG support. It does not enqueue any additional scripts or stylesheets in the frontend, ensuring it won’t affect the loading speed of your website. See plugin’s GitHub repo Support SVG Features Enables SVG uploads in WordPress media library Supports SVG thumbnail display in the Media Library Applies necessary security measures to sanitize SVG uploads Lightweight and does not enqueue any frontend scripts or stylesheets PRIVACY POLICY This plugin does not collect, log, sell or trade any kind of information about your website. You can easily verify that this plugin is not phoning home using a network traffic inspector like WireShark. ABOUT THE MAKER I am Sayedul Sayem, a Bangladeshi full-stack WordPress developer and free and open source enthusiast. You can contact me at my LinkedIn for consultation or just to say hello. I love talking to new people. So don’t hesitate.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C