SVG Support

SVG Support has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 8 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 6.4 out of 10. 2022 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (88%). Other recurring categories include Missing Authorization.

Every one of the 8 issues recorded for SVG Support has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, one record each. SVG Support is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.8/ 10
Patch Coverage100%
Open

0

Fixed

8

Get automatic notifications for all SVG Support vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-13340

SVG Support <= 2.5.16 - Authenticated (Author+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

8 records
SVG Support banner
Latestv2.6.1

SVG Support

Benbodhi

Author

Benbodhi

4.8(356)
96/100
Last Updated
2026-07-25 (2mo ago)
Active Installs
1,000,000+
Downloads
15,053,200
Requires WP
5.8+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2014-07-22 (12y ago)

The complete SVG solution for WordPress – secure, flexible, and easy to use. SVG Support enables secure SVG uploads with powerful features for both basic users and developers: ✨ Key Features: – Secure SVG uploads with automatic sanitization – Inline rendering for direct CSS/JS manipulation – File size optimization through minification – Role-based access control – Advanced developer options – Multisite compatible – Full Block Editor (Gutenberg) compatibility 🔒 Security First: – Built-in sanitization removes potentially harmful code – Role-based upload restrictions – Comprehensive MIME type validation 🎨 Designer Friendly: – Direct styling of SVG elements – Animation support – Custom class targeting – Automatic dimension handling 💻 Developer Ready: – Advanced mode for additional features – REST API support – Gutenberg compatible – Extensive hooks and filters Usage Basic Usage: – First, install and activate SVG Support via your WordPress dashboard – Upload SVG files to your media library like any other image – Works seamlessly with Image blocks, Cover blocks and featured images Advanced Usage: – Enable “Advanced Mode” for minification and inline rendering – Customize with hooks and filters for tailored functionality Block Editor Usage: – Use Advanced Mode to enable inline rendering: – Add the "style-svg" class to Image blocks – Add the "style-svg" class to Cover blocks to render SVG backgrounds inline – Use “Skip Nested SVGs” setting to control inline rendering of SVGs within Cover blocks Classic Editor Usage: – Use Advanced Mode to add the "style-svg" class to <img> tags for inline rendering – Enable “Auto Insert Class” option for automatic class insertion in Classic Editor Common Issues & Solutions: – SVG not displaying? Ensure dimensions are set in CSS. – Need help? Use the support tab and I will do my best to assist you. Spin up a test site With a single click, you can spin up a completely free test site to test SVG Support using TasteWP! No sign up, no cards, nothing! How cool is that? Give it a go: Click Here to spin up a test site in seconds Security SVG Support prioritizes security with automatic sanitization and role-based restrictions. Only trusted users should have upload permissions. Configure settings to balance functionality and security. Feedback I’m open to your suggestions and feedback – Thanks for using SVG Support! Follow @SVGSupport on Twitter Follow @benbodhi on Twitter Follow @benbodhi on Farcaster Note: I hope you like this plugin! Please take a moment to rate it. Development & Contributing The development version of SVG Support is maintained on GitHub. Feel free to contribute: Submit bug reports or feature suggestions: GitHub Issues Contribute code via Pull Requests Development repository: GitHub Translations Contribute translations here. New to translating? Check the Translator Handbook.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C